UPDATED 02:14 EDT / SEPTEMBER 08 2015

NEWS

Wireless Seagate hard drives vulnerable to hacking due to open root access

Owners of wireless hard drives made by Seagate Technologies PLC are at risk of being hacked after it was discovered that certain drives were shipped with a vulnerability that delivered hackers easy access.

First discovered by Tangible Security, Inc. last week, the vulnerability is a strange one simply due to the absurd simplicity of it: affected devices are shipped with an undocumented Telnet service that is accessible over the internet by using the default credentials of “root” as the username and a default password.

If that’s not bad enough, the credentials are hard-coded into the device so it’s not simply a matter of owners hitting the control panel of the hard drives and switching it off to fix it.

Given access, an attacker is able to covertly take control of the device, not only compromising the confidentiality of files stored on it but use it as a platform to conduct malicious operations beyond the device.

Even worse, the newly identified vulnerability is one of several for the device, with others including affected device firmware providing unrestricted file download capability and an upload vulnerability that allows others on a shared WiFi network to gain access.

Security researcher Kenn White commented on the vulnerability on Twitter Sunday, writing that “People don’t expect DOD-level security but, Seagate, please stop adding hidden hardcoded root logins to hard drives.”

Are you vulnerable?

The good news is that Seagate has come to the party and provided a firmware update that fixes the issue, however getting users to update their firmware on an external hard drive is another matter.

Affected Seagate devices include:

  • Seagate Wireless Plus Mobile Storage
  • Seagate Wireless Mobile Storage
  • LaCie FUEL

Firmware on the devices affected ranges from 2.2.0.005 and 2.3.0.014, dating to October 2014, however it is noted that other firmware versions may be affected.

“We urge users of these devices, including older and newer models, to download and install the latest firmware updates available from Seagate that address these vulnerabilities, “Tangible Security notes. “Failing to do so exposes those benefiting from the use of these devices to cybercrime risks.”

If you are using a Seagate device that needs to be updated and you’re looking for the new firmware, it can be downloaded here.

Image credit: vector_tf/Flickr/CC by 2.0

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.