← back
CVE-2020-6627

CVE-2020-6627

CVSS 9.8 CRITICALEPSS 12.5%CWE-78
Vexday Risk Score
53Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 12.5%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
06 Dec 2022Published on NVD
25 May 2023Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_helper.php by leveraging the "start" state and sending a check_device_name request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →