PT-2022-9051 · Seagate · Seagate Central Nas

Ege Balci

·

Published

2022-12-06

·

Updated

2025-04-23

·

CVE-2020-6627

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Seagate Central NAS versions STCG2000300, STCG3000300, and STCG4000300
Description The web-management application on the affected devices allows OS command injection via mv backend launch in cirrus/application/helpers/mv backend helper.php by leveraging the "start" state and sending a check device name request.
Recommendations For versions STCG2000300, STCG3000300, and STCG4000300, consider restricting access to the mv backend launch function in cirrus/application/helpers/mv backend helper.php to minimize the risk of exploitation. As a temporary workaround, avoid sending check device name requests when the device is in the "start" state until a patch is available.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-6627

Affected Products

Seagate Central Nas