Vulnerability CVE-2015-2875


Published: 2015-12-31

Description:
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session.

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.8/10
6.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Seagate -> Goflex sattelite 
Seagate -> Wireless mobile storage 
Seagate -> Wireless plus mobile storage 
Lacie -> Lac9000436u firmware 
Lacie -> Lac9000464u firmware 

 References:
https://www.kb.cert.org/vuls/id/GWAN-A26L3F
https://www.kb.cert.org/vuls/id/GWAN-9ZGTUH
https://www.kb.cert.org/vuls/id/903500

Copyright 2024, cxsecurity.com

 

Back to Top