CVE-2018-5347 is a critical unauthenticated command injection vulnerability affecting Seagate Personal Cloud devices. Attackers can exploit mishandled shell metacharacters in the uploadTelemetry and getLogs functions to execute arbitrary commands remotely without authentication. This flaw carries a CVSS score of 9.8 (Critical), indicating high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an exploit is publicly available on ExploitDB, and the vulnerability has garnered community discussion and media coverage, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:seagate:personal_cloud_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.