Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-6627


The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.


Published

2022-12-06T15:15:15.730

Last Modified

2025-04-23T15:15:46.020

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System seagate stcg2000300_firmware - Yes
Hardware seagate stcg2000300 - No
Operating System seagate stcg3000300_firmware - Yes
Hardware seagate stcg3000300 - No
Operating System seagate stcg4000300_firmware - Yes
Hardware seagate stcg4000300 - No

References