CVE-2015-2874

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
31/12/2015
Last modified:
12/04/2025

Description

Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:seagate:wireless_mobile_storage:*:*:*:*:*:*:*:*
cpe:2.3:h:seagate:wireless_plus_mobile_storage:*:*:*:*:*:*:*:*
cpe:2.3:h:lacie:lac9000436u:*:*:*:*:*:*:*:*
cpe:2.3:h:lacie:lac9000464u:*:*:*:*:*:*:*:*
cpe:2.3:o:lacie:lac9000436u_firmware:*:*:*:*:*:*:*:* 2.3.0.014 (including)
cpe:2.3:o:lacie:lac9000464u_firmware:*:*:*:*:*:*:*:* 2.3.0.014 (including)
cpe:2.3:h:seagate:goflex_sattelite:*:*:*:*:*:*:*:*