Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Seagate Patches Vulnerabilities in Wireless Hard Drives

Seagate has released firmware updates to address several vulnerabilities affecting the company’s wireless storage devices.

Seagate has released firmware updates to address several vulnerabilities affecting the company’s wireless storage devices.

The flaws, reported by researchers at Virginia-based security solutions provider Tangible Security, can be exploited by remote, unauthenticated attackers to access arbitrary files on the hard drive and gain root access to the device. The issues affect Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL, which are products designed for personal use.Seagate wireless storage

The security holes have been confirmed to exist in versions 2.2.0.005 and 2.3.0.014 of the firmware (released in October 2014), but other versions may be impacted as well. Seagate patched the vulnerabilities with the release of version 3.4.1.105 of the firmware, CERT said in an advisory published this week.

Tangible Security’s Allen Harper, one of the experts involved in the analysis of Seagate hard drives, confirmed for SecurityWeek that the updates released by Seagate patch the vulnerabilities.

Tangible Security said the vulnerabilities were reported to Seagate on March 18 and they were confirmed by the vendor on March 30. The patches were tested and confirmed by the security firm on July 8.

According to the advisory published by CERT, a total of three vulnerabilities have been identified in Seagate’s wireless hard drives. One of them involves the use of hardcoded credentials — the default username and password is “root” — that can be utilized to access undocumented Telnet services (CVE-2015-2874).

Another flaw is a direct request issue (CVE-2015-2875) that could allow anonymous attackers with wireless access to the storage unit to download files from anywhere on the file system. The vulnerability is related to the device’s unrestricted file download feature provided in default configurations.

The last security bug can be exploited by attackers to wirelessly upload potentially malicious files to the device’s /media/sda2 filesystem, which is reserved for file sharing (CVE-2015-2876).

“Seagate was made aware of vulnerabilities in its consumer based wireless hard drives. Seagate has patched the vulnerabilities and issued a firmware update that is available to customers on Seagate.com and through a link on the CERT notification. The firmware update addresses all security concerns with these vulnerabilities,” Seagate told SecurityWeek.

Advertisement. Scroll to continue reading.

“Affected users are encouraged to update the firmware as soon as possible. Customers may download the firmware from Seagate’s website,” the company added. “Seagate encourages any customer encountering issues to contact customer service at 1-800-Seagate.”

*Updated with statement from Seagate

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

Vulnerabilities

The latest Chrome update brings patches for eight vulnerabilities, including seven reported by external researchers.