VYPR
Vendor

Seagate

Products
23
CVEs
33
Across products
57
Status
Private

Products

23

Recent CVEs

33
View all 33 CVEs →
  • CVE-2018-5347CriJan 12, 2018
    risk 0.71cvss 9.8epss 0.54

    Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

  • CVE-2014-8687CriJun 8, 2017
    risk 0.70cvss 9.8epss 0.44

    Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

  • CVE-2014-3206CriFeb 23, 2018
    risk 0.68cvss 9.8epss 0.51

    Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.

  • CVE-2013-6924CriOct 11, 2017
    risk 0.68cvss 9.8epss 0.15

    Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.

  • CVE-2018-12295CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.01

    SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.

  • CVE-2014-3205CriFeb 23, 2018
    risk 0.64cvss 9.8epss 0.03

    backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.

  • CVE-2015-2874CriDec 31, 2015
    risk 0.64cvss 9.8epss 0.04

    Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET…

  • CVE-2015-2876HigDec 31, 2015
    risk 0.57cvss 8.8epss 0.03

    Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2…

  • CVE-2018-12296HigMay 13, 2019
    risk 0.50cvss 7.5epss 0.11

    Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authentication via empty POST requests.

  • CVE-2018-12301HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.01

    Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.

  • CVE-2018-12298HigMay 13, 2019
    risk 0.49cvss 7.5epss 0.02

    Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.

  • CVE-2017-18263HigApr 28, 2018
    risk 0.49cvss 7.5epss 0.04

    Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.

  • CVE-2015-2875HigDec 31, 2015
    risk 0.49cvss 7.5epss 0.03

    Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download…

  • CVE-2025-9267HigSep 26, 2025
    risk 0.46cvss epss 0.00

    In Seagate Toolkit on Windows a vulnerability exists in the Toolkit Installer prior to versions 2.35.0.6 where it attempts to load DLLs from the current working directory without validating their origin or integrity. This behavior can be exploited by placing a malicious DLL in…

  • CVE-2025-9043MedAug 14, 2025
    risk 0.44cvss epss 0.00

    The service executable path in Seagate Toolkit on Versions prior to 2.34.0.33 on Windows allows an attacker with Admin privileges to exploit a vulnerability as classified under CWE-428: Unquoted Search Path or Element. An attacker with write permissions to the root could place a…

  • CVE-2018-12304MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.

  • CVE-2018-12302MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.01

    Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.

  • CVE-2018-12300MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.03

    Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.

  • CVE-2018-12297MedMay 13, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.

  • CVE-2018-12303MedMay 13, 2019
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.