peter bassill · operator
$ cve CVE-2015-2874 JSON

CVE-2015-2874

9.8
CRITICAL · CVSS 3.0 · EPSS 4.2% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.15% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-255
On CISA KEVno
Public exploitnone known
Published2015-12-31
Last modified2026-06-17

Affected (7)

VendorProduct
lacielac9000436u
lacielac9000436u firmware
lacielac9000464u
lacielac9000464u firmware
seagategoflex sattelite
seagatewireless mobile storage
seagatewireless plus mobile storage

References

→ the Explorer  ·  watch your stack  ·  NVD