Seagate Technology's vulnerability footprint centers on a focused range of network-attached storage and firmware products, which despite a modest product count occupy a prominent position in the landscape due to their widespread deployment in both consumer and enterprise environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the appeal of storage devices as targets for data exfiltration, ransomware staging, and lateral movement. The exposure recurs across NAS operating systems and device firmware through weakness classes including cross-site scripting, path traversal, OS command injection, and cross-site request forgery—web and input-handling flaws that are characteristic of embedded management interfaces and firmware update mechanisms. Defenders should treat Seagate storage appliances, particularly internet-facing or management-accessible instances, as high-priority patching targets and inventory the affected product lines to ensure timely remediation. Live exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Seagate Technology over time
Of all the CVEs published by Seagate Technology as a CNA, 0.0% affect products that Seagate Technology develops as a vendor.
Of all the CVEs published that affect products developed by Seagate Technology, 0.0% are self-published by Seagate Technology as a CNA.
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8687CRITICAL Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to c | Jun 8, 2017 | 9.8 | 73 | NO | YES |
CVE-2018-5347CRITICAL Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the f | Jan 12, 2018 | 9.8 | 70 | NO | YES |
CVE-2014-3206CRITICAL Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backu | Feb 23, 2018 | 9.8 | 63 | NO | YES |
CVE-2013-6924CRITICAL Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlia | Oct 11, 2017 | 9.8 | 50 | NO | YES |
CVE-2020-6627CRITICAL The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/help | Dec 6, 2022 | 9.8 | 47 | NO | YES |
CVE-2018-12296HIGH Insufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain information about the NAS without authenticat | May 13, 2019 | 7.5 | 40 | NO | YES |
CVE-2018-18471CRITICAL /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can be chained with an SSRF bug to | Jun 19, 2019 | 9.8 | 34 | NO | NO |
CVE-2018-12300MEDIUM Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter. | May 13, 2019 | 6.1 | 32 | NO | YES |
CVE-2018-12295CRITICAL SQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the dirId URL parameter. | May 13, 2019 | 9.8 | 30 | NO | NO |
CVE-2014-3205CRITICAL backupmgt/pre_connect_check.php in Seagate BlackArmor NAS contains a hard-coded password of '!~@##$$%FREDESWWSED' for a backdoor user. | Feb 23, 2018 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Seagate Technology.
Media articles that mention a CVE ID that affects a product developed by Seagate Technology — matched by CVE ID, not by vendor name.