A security advisory published on September 1 and revised on September 2 reveals that Seagate's wireless hard drives contain multiple vulnerabilities, including one that exploits hard-coded credentials.
The vulnerability allows exploits in the Telnet service running on the drives, using the default credentials “root” as the username and the default password, according to Tangible Security , which discovered it.
The main issue here is that the credentials encoded in the disk's firmware are always the same, allowing attackers to easily exploit the vulnerability on all affected disks.
The affected hard drives of the company are the following:
- Seagate Wireless Plus Mobile Storage
- Wireless Mobile Storage
- LaCie FUEL
These disks are also affected by two other vulnerabilities. The first exists if the default disk drive setting has not been modified. This allows attackers with (wireless) access to the compromised devices to download all disk files without authentication.
The other vulnerability provides attackers with the means to upload files to the disks under a default parameter setting.
All three vulnerabilities provide attackers with full access to the files stored on these wireless drives, and often the device owner is unaware.
The company has released a new firmware for all of the above drives. So end users and administrators should apply these patches immediately. If you are interested, you should know the serial number of your drive.
The easiest way to find the serial number of Seagate drives is to use the company's Drive Detect application
It would be advisable to create backups of your data before applying the new firmware.
