CVE-2018-5347 EXPLOIT
9.8
CRITICAL · CVSS 3.0 · EPSS 54.2% (pctl 99)
Patch early
A public exploit exists.
Description
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 54.16% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-12 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| seagate | personal cloud |
| seagate | personal cloud firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Seagate Personal Cloud - Multiple Vulnerabilities | 2018-01-11 |
References
→ the Explorer · watch your stack · NVD