First published: Tue Dec 06 2022(Updated: )
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
Credit: Ege Balci cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seagate Stcg2000300 Firmware | ||
Seagate Stcg2000300 | ||
Seagate Stcg3000300 Firmware | ||
Seagate Stcg3000300 | ||
Seagate Stcg4000300 Firmware | ||
Seagate Stcg4000300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.