Vulnerability CVE-2015-2876


Published: 2015-12-31

Description:
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
BSNL Teracom Router Firmware Rewrite / Link Modification
Ajay Gowtham
07.09.2016

CVSS2 => (AV:A/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
8.3/10
10/10
6.5/10
Exploit range
Attack complexity
Authentication
Adjacent network
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Seagate -> Goflex sattelite 
Seagate -> Wireless mobile storage 
Seagate -> Wireless plus mobile storage 
Lacie -> Lac9000436u firmware 
Lacie -> Lac9000464u firmware 

 References:
https://www.kb.cert.org/vuls/id/GWAN-A26L3F
https://www.kb.cert.org/vuls/id/GWAN-9ZGTUH
https://www.kb.cert.org/vuls/id/903500

Copyright 2024, cxsecurity.com

 

Back to Top