CVE-2014-8687

Severity CVSS v4.0:
Pending analysis
Type:
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Publication date:
08/06/2017
Last modified:
20/04/2025

Description

Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:seagate:business_nas_firmware:2014.00319:*:*:*:*:*:*:*
cpe:2.3:h:seagate:business_nas:-:*:*:*:*:*:*:*