PT-2014-1969 · Seagate · Seagate Business Nas
Oj Reeves
·
Published
2014-10-07
·
Updated
2017-06-16
·
CVE-2014-8687
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Seagate Business NAS devices with firmware before 2015.00322
Description
The issue is caused by the use of defective or risky cryptographic algorithms in the embedded software of Business NAS devices, allowing remote attackers to execute arbitrary code with root privileges. This is achieved by leveraging the use of a static encryption key to create session tokens.
Recommendations
For Seagate Business NAS devices with firmware before 2015.00322, update the firmware to version 2015.00322 or later to resolve the issue.
Exploit
Fix
Use of a Broken Cryptographic Algorithm
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Seagate Business Nas