CVE-2014-8687: Seagate Business NAS Firmware

Critical severity, CVSS 9.8. EPSS: 43.8% chance of exploitation in the next 30 days.

Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session tokens.

Affected products

  • Seagate Business NAS Firmware: version 2014.00319 only

Published 2017-06-08. Last modified 2026-06-17.