CVE-2015-2874
9.8
CRITICAL · CVSS 3.0 · EPSS 4.2% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 have a default password of root for the root account, which allows remote attackers to obtain administrative access via a TELNET session.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.15% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-255 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2015-12-31 |
| Last modified | 2026-06-17 |
Affected (7)
| Vendor | Product |
|---|---|
| lacie | lac9000436u |
| lacie | lac9000436u firmware |
| lacie | lac9000464u |
| lacie | lac9000464u firmware |
| seagate | goflex sattelite |
| seagate | wireless mobile storage |
| seagate | wireless plus mobile storage |
References
→ the Explorer · watch your stack · NVD