PoC Index

CVE-2018-5347

HIGH 10.0EPSS 54.2%

Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

CVSS v3.0
9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
54.16% chance of exploitation in the next 30 days, 99th percentile
Published
2018-01-12
Updated
2024-08-05

ExploitDB entries (1)

References

Related