CVE-2015-2876

Severity

83%

Complexity

65%

Confidentiality

165%

CWE-434: Unrestricted Upload of File with Dangerous Type

Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.

CWE-434: Unrestricted Upload of File with Dangerous Type

CVSS 3.0 Base Score 8.8. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 8.3. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: low. CVSS Vector: (AV:A/AC:L/Au:N/C:C/I:C/A:C).

Overview

Type

Seagate

First reported 9 years ago

2015-12-31 05:59:00

Last updated 9 years ago

2015-12-31 15:46:00

Affected Software

Seagate Wireless Mobile Storage

Seagate Wireless Plus Mobile Storage

Seagate GoFlex Sattelite

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.