6.8
CVSSv2

CVE-2013-6922

Published: 21/01/2014 Updated: 22/01/2014
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote malicious users to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3) delete user accounts; (4) perform a factory reset; (5) perform a device reboot; or (6) add, (7) modify, or (8) delete shares and volumes.

Vulnerable Product Search on Vulmon Subscribe to Product

seagate blackarmor_nas_220_firmware sg2000-2000.1331

seagate blackarmor_nas_220 st320005lsa10g-rk

seagate blackarmor_nas_220 st340005lsa10g-rk

seagate blackarmor_nas_220 stav6000100

Exploits

# Exploit Title: Seagate BlackArmor NAS - Cross Site Request Forgery # Google Dork: N/A # Date: 04-01-2014 # Exploit Author: Jeroen - IT Nerdbox # Vendor Homepage: wwwseagatecom/ # Software Link: wwwseagatecom/support/downloads/item/banas-220-firmware-master-dl/ # Version: sg2000-20001331 # Tested on: N/A # CVE : CVE-2013 ...
Seagate BlackArmor NAS sg2000-20001331 suffers from a cross site request forgery vulnerability ...