PT-2017-3506 · Seagate · Seagate Personal Cloud
Yorick Koster
·
Published
2017-10-16
·
Updated
2019-10-03
·
CVE-2018-5347
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Seagate Personal Cloud (affected versions not specified)
Description
The issue is related to the Media Server component of Seagate Personal Cloud, specifically with the
uploadTelemetry and getLogs functions in views.py. It is caused by the failure to neutralize special elements used in a command, which can be exploited to execute arbitrary commands with root privileges. The vulnerability is also described as an unauthenticated command injection, where .psp URLs handled by the fastcgi.server component mishandle shell metacharacters.Recommendations
For the affected Media Server component, consider disabling the
uploadTelemetry and getLogs functions until a patch is available.
Restrict access to the views.py file to minimize the risk of exploitation.
Avoid using the fastcgi.server component to handle .psp URLs in the affected Media Server component until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Seagate Personal Cloud