Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Seagate Technology

First CVE: May 25, 2012Active for: 14 yearsTotal CVEs: 28
49.6
VTI Score
High

Seagate Technology's vulnerability footprint centers on a focused range of network-attached storage and firmware products, which despite a modest product count occupy a prominent position in the landscape due to their widespread deployment in both consumer and enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the appeal of storage devices as targets for data exfiltration, ransomware staging, and lateral movement. The exposure recurs across NAS operating systems and device firmware through weakness classes including cross-site scripting, path traversal, OS command injection, and cross-site request forgery—web and input-handling flaws that are characteristic of embedded management interfaces and firmware update mechanisms. Defenders should treat Seagate storage appliances, particularly internet-facing or management-accessible instances, as high-priority patching targets and inventory the affected product lines to ensure timely remediation. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Seagate Technology over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 25, 2012
14 years ago
Most Recent CVE
Dec 6, 2022
1,326 days ago

Self-Reporting Analysis

Of all the CVEs published by Seagate Technology as a CNA, 0.0% affect products that Seagate Technology develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 5 (100.0%)

Of all the CVEs published that affect products developed by Seagate Technology, 0.0% are self-published by Seagate Technology as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 28 (100.0%)

Products(25 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2014-8687CRITICAL
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to c
Jun 8, 20179.873NOYES
CVE-2018-5347CRITICAL
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the f
Jan 12, 20189.870NOYES
CVE-2014-3206CRITICAL
Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backu
Feb 23, 20189.863NOYES
CVE-2013-6924CRITICAL
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlia
Oct 11, 20179.850NOYES
CVE-2020-6627CRITICAL
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/help
Dec 6, 20229.847NOYES
CVE-2018-12296HIGH
Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authenticat
May 13, 20197.540NOYES
CVE-2018-18471CRITICAL
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to
Jun 19, 20199.834NONO
CVE-2018-12300MEDIUM
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
May 13, 20196.132NOYES
CVE-2018-12295CRITICAL
SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter.
May 13, 20199.830NONO
CVE-2014-3205CRITICAL
backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user.
Feb 23, 20189.830NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
39%
29%
32%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network21 (75.0%)
Unknown3 (10.7%)
Physical3 (10.7%)
Adjacent Network1 (3.6%)
Attack Complexity
Low22 (78.6%)
High3 (10.7%)
Unknown3 (10.7%)
User Interaction
None19 (67.9%)
Unknown3 (10.7%)
Required6 (21.4%)
Privileges Required
Low2 (7.1%)
High0 (0.0%)
None23 (82.1%)
Unknown3 (10.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.6% of CVEs· 98th percentile
Nuclei
3 CVEs
10.7% of CVEs· 96th percentile
ExploitDB
6 CVEs
21.4% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Seagate Technology.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Seagate Technology — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Seagate Technology's Products

View all 2 CNAs →

Top CWEs