Vulnerabilities > CVE-2015-2874 - Credentials Management vulnerability in multiple products

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
seagate
lacie
CWE-255
critical

Summary

Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/134986/KL-001-2015-007.txt
idPACKETSTORM:134986
last seen2016-12-05
published2015-12-18
reporterMatthew Bergin
sourcehttps://packetstormsecurity.com/files/134986/Seagate-GoFlex-Satellite-Remote-Telnet-Default-Password.html
titleSeagate GoFlex Satellite Remote Telnet Default Password

The Hacker News