vendor:
Central
by:
Jeremy Brown
7.5
CVSS
HIGH
Passwordless root login via FTP to retrieve archive_accounts.ser file which contains access tokens
287
CWE
Product Name: Central
Affected Version From: 2014.0410.0026-F
Affected Version To: 2014.0410.0026-F
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Seagate Central Remote Facebook Access Token Exploit
Seagate Central stores linked Facebook account access tokens in /etc/archive_accounts.ser and this exploit takes advantage of two bugs: 1) Passwordless root login via FTP to retrieve archive_accounts.ser file which contains access tokens and 2) Reuses the unencrypted and unprotected (-rw-r--r--) access tokens for a chosen scope to return data.
Mitigation:
Seagate scheduled updates to go live on April 28th, 2015.