Seagate Personal Cloud SRN21C...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Abstract Seagate Personal Cloud is a consumer-grade Network-Attached Storage device (NAS). It was found that Seagate Media Server is affected by multiple SQL injection vulnerabilities. An unauthenticated attacker can exploit this issue to retrieve or modify arbitrary data in the database used by Seagate Media Server. Seagate Media Server uses a separate SQLite3 database, which limits what the attacker can do with this issue. ### Tested versions This issue was tested on a Seagate Personal Cloud model SRN21C running firmware versions 4.3.16.0 and 4.3.18.0. It is likely that other devices/models are also affected. ### Fix These vulnerabilities have been fixed in firmware version 4.3.19.3. ### Introduction Seagate Personal Cloud is a consumer-grade Network-Attached Storage device (NAS). Personal Cloud is deployed with the Seagate Media Server application that allows users to easily access their movies, music, and photos. The Seagate Media Server is accessible without...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息