First published: Fri Jan 12 2018(Updated: )
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seagate Personal Cloud Firmware | ||
Seagate Personal Cloud |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.