First published: Thu Dec 31 2015(Updated: )
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seagate GoFlex Satellite | ||
Seagate Wireless Plus Mobile Storage | ||
Seagate Wireless Mobile Storage | ||
Lacie Lac9000436u Firmware | ||
Lacie Lac9000464u Firmware | ||
LaCie LaC9000436U | <=2.3.0.014 | |
Lacie Lac9000464u | <=2.3.0.014 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2875 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2015-2875, update the firmware of affected Seagate and LaCie devices to version 3.4.1.105 or later.
CVE-2015-2875 affects Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, and Seagate Wireless Plus Mobile Storage devices.
CVE-2015-2875 is an absolute path traversal vulnerability allowing unauthorized access to files.
Yes, CVE-2015-2875 can be exploited remotely through a crafted download request during a Wi-Fi session.