PT-2014-2001 · Seagate · Seagate Blackarmor Nas

Publicado

2014-05-03

·

Atualizado

2018-03-18

·

CVE-2014-3205

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Seagate BlackArmor NAS (affected versions not specified)
Description The issue is related to the backupmgt/pre connect check.php component of the Seagate BlackArmor NAS, which contains a hard-coded password for a backdoor user. This could allow a remote attacker to gain full access to the device with root privileges. The hard-coded password is '!~@##$$%FREDESWWSED'.
Recommendations For Seagate BlackArmor NAS, consider changing the hard-coded password '!~@##$$%FREDESWWSED' for the backdoor user in the backupmgt/pre connect check.php component to prevent unauthorized access. As a temporary workaround, consider disabling the backupmgt/pre connect check.php component until a patch is available. Restrict access to the device to minimize the risk of exploitation.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00627
CVE-2014-3205

Produtos afetados

Seagate Blackarmor Nas