peter bassill · operator
$ cve CVE-2018-5347 JSON

CVE-2018-5347 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 54.2% (pctl 99)

Patch early

A public exploit exists.

Description

Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS54.16% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2018-01-12
Last modified2026-06-17

Affected (2)

VendorProduct
seagatepersonal cloud
seagatepersonal cloud firmware

Public exploits

SourceTitleDate
exploit-dbSeagate Personal Cloud - Multiple Vulnerabilities2018-01-11

References

→ the Explorer  ·  watch your stack  ·  NVD