Vulnerability Description
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Seagate | Blackarmor Nas 220 Firmware | sg2000-2000.1331 |
| Seagate | Blackarmor Nas 220 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/124688/Seagate-BlackArmor-NAS-sg2000-2000.1ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/64655Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90109Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/124688/Seagate-BlackArmor-NAS-sg2000-2000.1ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/64655Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90109Third Party AdvisoryVDB Entry
FAQ
What is CVE-2013-6924?
CVE-2013-6924 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
How severe is CVE-2013-6924?
CVE-2013-6924 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-6924?
Check the references section above for vendor advisories and patch information. Affected products include: Seagate Blackarmor Nas 220 Firmware, Seagate Blackarmor Nas 220.