PT-2017-3506 · Seagate · Seagate Personal Cloud

Yorick Koster

·

Published

2017-10-16

·

Updated

2019-10-03

·

CVE-2018-5347

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Seagate Personal Cloud (affected versions not specified)
Description The issue is related to the Media Server component of Seagate Personal Cloud, specifically with the uploadTelemetry and getLogs functions in views.py. It is caused by the failure to neutralize special elements used in a command, which can be exploited to execute arbitrary commands with root privileges. The vulnerability is also described as an unauthenticated command injection, where .psp URLs handled by the fastcgi.server component mishandle shell metacharacters.
Recommendations For the affected Media Server component, consider disabling the uploadTelemetry and getLogs functions until a patch is available. Restrict access to the views.py file to minimize the risk of exploitation. Avoid using the fastcgi.server component to handle .psp URLs in the affected Media Server component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00352
CVE-2018-5347

Affected Products

Seagate Personal Cloud