HTTP: Seagate Business NAS Pre-Authentication Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Seagate Business Network Attached Storage. A successful attack can lead to arbitrary code execution.

Extended Description

Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

References

CVE: CVE-2014-8687

Short Name
HTTP:MISC:SEAGATE-NAS-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Business CVE-2014-8687 Code Execution NAS Pre-Authentication Remote Seagate
Release Date
03/02/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

10.0

Found a potential security threat?