CVE Tools

CVE-2018-5347

Published: Jan 12, 2018Updated: Nov 21, 2024 Sources: CVE List NVD BDUCWE-78

Description

Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

In plain language

AI Worth attention

CVE-2018-5347 is a serious security flaw in Seagate Personal Cloud that can let an attacker run commands on your device over the network without logging in. If your Personal Cloud is reachable from the internet, you should act now by restricting access and applying any available firmware update.

Executive summary

CVE-2018-5347 is an unauthenticated command injection in Seagate Media Server inside Seagate Personal Cloud (uploadTelemetry and getLogs endpoints in views.py), where crafted requests can include shell metacharacters that get executed by the fastcgi.server handling of .psp URLs.

If affected, business impact
Full device takeoverBusiness data theft riskService disruptionRansomware entry point

What to do now

  1. Check whether your Seagate Personal Cloud device is running Seagate Media Server and whether it’s exposed to the network (especially the internet).
  2. If it is exposed, immediately restrict access so it’s reachable only from your office/VPN (close public ports and remove any direct internet routing).
  3. Check Seagate for a firmware/media-server update that removes this command injection (the vendor fix was described as restricting access until an update is released).
  4. Apply the update as soon as it becomes available, then re-verify that the device is no longer publicly reachable.
Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

seagate
commercial·USaka seagate nas os, seagate technology
Seagate Technology LLC
commercial·USaka goflex satellite, lacie fuel, wireless mobile storage
and 1 more affected products View all →

Exploitability

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2018-5347 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows