HomeSecuritySeagate announces fix for Business Storage 2-Bay NAS in May

Seagate announces fix for Business Storage 2-Bay NAS in May

nas

Administrators of Seagate's Business Storage 2-Bay NAS will have to wait until May for the company to release a new fix to fix the bug that allowed remote code execution, as discovered earlier this month.

Security consulting firm Beyond Binary revealed on March 1 that the firmware of some NAS devices from Seagatecontained versions of PHP and CodeIgniter with known vulnerabilities.

The default configuration for Business Storage 2-Bay NAS restricts access to the storage unit from a remote location.

At the time of the investigation, the Australian security firm had found more than 2,500 NAS devices running the flawed firmware version 2014.00319. The researchers used the Shodan search engine to find the connections that had been made.

Seagate immediately downplayed the security risk these systems pose, saying it was "a fairly unlikely scenario" for a NAS to be hacked over the internet, but it did release guidance for administrators on how to secure the devices.

The number of units at risk may not be large, but considering that the product is intended for professional use, companies using it could suffer quite a bit of damage, in terms of their data.

Before the research results were made public, the security firm first contacted Seagate in October 2014. Seagate acknowledged the problem immediately but did not indicate that it would begin building new firmware.

Until the new update, which will be available from May, the exact release date is not yet available, Seagate recommends that users disable UPnP port forwarding and FTP service from the Business Storage NAS management page.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS