First published: Thu Dec 31 2015(Updated: )
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lacie Lac9000436u | ||
Lacie Lac9000464u | ||
Lacie Lac9000436u Firmware | <=2.3.0.014 | |
Lacie Lac9000464u Firmware | <=2.3.0.014 | |
Seagate Wireless Mobile Storage | ||
Seagate Wireless Plus Mobile Storage | ||
Seagate Goflex Sattelite |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2876 has been assigned a critical severity rating due to the potential for remote code execution.
To mitigate CVE-2015-2876, update the firmware of affected Seagate and LaCie devices to version 3.4.1.105 or later.
CVE-2015-2876 affects Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware versions prior to 3.4.1.105.
CVE-2015-2876 is exploitable remotely, allowing attackers to upload malicious files without local access.
Exploiting CVE-2015-2876 can result in arbitrary code execution, allowing attackers to fully compromise affected devices.