Advertisement






Seagate Media Server Path Traversal

CVE Category Price Severity
CVE-2020-9482 CWE-22 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2018-04-20
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018040167

Below is a copy:

Seagate Media Server Path Traversal
------------------------------------------------------------------------
Seagate Media Server path traversal vulnerability
------------------------------------------------------------------------
Yorick Koster, September 2017

------------------------------------------------------------------------
Abstract
------------------------------------------------------------------------
Seagate Personal Cloud is a consumer-grade Network-Attached Storage
device (NAS). It was found that Seagate Media Server is vulnerable to
path traversal that allows unauthenticated attackers to download
arbitrary files from the NAS. Since Seagate Media Server runs with root
privileges it is possible to exploit this issue to retrieve sensitive
information from the NAS.

------------------------------------------------------------------------
Tested versions
------------------------------------------------------------------------
This issue was tested on a Seagate Personal Cloud model SRN21C running
firmware versions 4.3.16.0 and 4.3.18.0. It is likely that other
devices/models are also affected.

------------------------------------------------------------------------
Fix
------------------------------------------------------------------------
This issue has been fixed in firmware version 4.3.18.4.

------------------------------------------------------------------------
Details
------------------------------------------------------------------------
https://sumofpwn.nl/advisory/2017/seagate-media-server-path-traversal-vulnerability.html


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum