CVE-2015-2876
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unrestricted file upload vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to execute arbitrary code by uploading a file to /media/sda2 during a Wi-Fi session.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.77% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- lacie/lac9000436u firmware · lacie/lac9000464u firmware · seagate/wireless mobile storage · seagate/wireless plus mobile storage · seagate/goflex sattelite
- Source
- cret@cert.org
References
- https://www.kb.cert.org/vuls/id/903500Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/GWAN-9ZGTUHThird Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/GWAN-A26L3FThird Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/903500Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/GWAN-9ZGTUHThird Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/GWAN-A26L3FThird Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.