CVE-2020-6627: Command Injection
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6627?
CVE-2020-6627 has been classified as a critical vulnerability due to its potential for OS command injection.
How do I fix CVE-2020-6627?
To fix CVE-2020-6627, update the firmware of your Seagate Central NAS to the latest version provided by Seagate.
What devices are affected by CVE-2020-6627?
CVE-2020-6627 affects Seagate Central NAS models STCG2000300, STCG3000300, and STCG4000300.
What is OS command injection in CVE-2020-6627?
OS command injection in CVE-2020-6627 allows an attacker to execute arbitrary operating system commands on the vulnerable device.
What could happen if CVE-2020-6627 is exploited?
If exploited, CVE-2020-6627 could lead to unauthorized access and control over the affected Seagate NAS device.