Free standard shipping on all orders over $100 Shop now
Resource Center Blog Open Source Partners
Search
Open

Your data deserves world-class protection

Learn about the end-to-end data protection built into our firmware, hardware, and processes.

Icon consisting of a lock in the center of a shield with an overlapping circle encasing a check mark indicates secured data.
Drive, shield/lock, and circular arrows icons represent trusted products, data security, and reliable delivery.

Built to resist. Designed to protect.

Security is woven into the fabric of everything we build—empowering our customers with trustworthy data storage solutions that protect what matters most. Seagate products are engineered to stand strong against cyber threats—built with secure features, hardened manufacturing, and secure-by-design principles. Our robust public key infrastructure and certified cryptographic services safeguard data at every stage. With ongoing resilience testing and ISO 20243 product security certification, we ensure a trusted lifecycle from production to deployment.

Comprehensive encryption for complete confidence.

In today’s data-driven world, information is one of your most valuable business assets—and it demands protection. That’s why security experts advocate for a comprehensive approach that combines both hardware- and software-based encryption. As storage performance and accessibility accelerate, encrypting every bit of your business data isn’t just best practice—it’s essential.

Stay informed with security advisories.

Read advisoriesClose advisories
Read advisoriesClose advisories

Issue

Products

Solution

Release Date

CVE-2022-37434
CVE-2018-25032

RAID enabled SeaChest and SeaDragon

Some versions of RAID enabled SeaDragon and RAID enabled SeaChest use a third-party RAID library that contains zlib vulnerabilities. The build dates for the affected versions are as follows: Build dates for SeaDragon_<ToolName>_R and SeaChest_<ToolName>_R:

April 8 - 15, 2022
July 26 - Aug 4, 2022
March 2 - 9, 2023
March 28 - April 4, 2023

Running the tool with the following command will display the build date and "RAID Enabled" in the banner: --version

RAID enabled SeaDragon_<ToolName>_R and SeaChest_<ToolName>_R with a build date of December 4, 2023, and later have remediated the vulnerabilities for the following: Microchip, PMC and HPE SmartRAID or SmartHBA Controllers.

·          Latest version of SeaChest

·          For the latest version of SeaDragon, contact your Seagate Customer Support Engineer

At this time, Windows versions of SeaDragon and SeaChest released December 4, 2023, or later do not support Adaptec Controllers Series 8. There is not a current workaround for these controllers on Windows.

December 4, 2023

CVE-2023-48795

Exos X 3005 Hybrid Storage Arrays

Exos X 4005 Hybrid Storage Arrays

Exos X 5005 Hybrid Storage Arrays

Vulnerability is exploited with specific ciphers: there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). Mitigations by removal of the ciphers can done on either server side or client side to be effective.

For the client side, an end user can remove the two ciphers from the default offered ciphers.

For the server side, Exos X firmware G280R014-01 will not be remediated.

Products are EOL. Fix and intercept with future planned release.

This column will be updated if a fix becomes available.

CVE-2022-38392

Seagate Backup Plus Desktop 4TB (STDT4000100)

Seagate products are designed to operate within defined acoustic, shock, and vibration tolerances. Exceeding defined tolerances, as stated in the product specifications, may cause product failures and void the product warranty. Users should ensure the products operate in an environment that meets Seagate's operating environment specifications

8/29/23

Pre-Auth Remote Code Execution (RCE) Vulnerability

LaCie Cloudbox

2.6.11.1 (Cloudbox)

6/17/2021

 

NetworkSpace 2 Products:

 

·          Network Space 2

·          Network Space Max

·          d2 Network 2

·          2big Network 2

·          5big Network 2

2.2.12.3

 

·          Network Space 2

·          Network Space Max

·          d2 Network 2

·          2big Network 2

·          5big Network 2

6/17/2021

 CVE-2016-2118 - (a.k.a Badlock)

LaCie 5Big NAS Pro
LaCie 2Big NAS
LaCie Cloudbox

4.2.11.1
4.2.11.1
2.6.11.0

6/15/2016

 CVE-2016-2118 - (a.k.a Badlock)

Seagate NAS
Seagate NAS Pro
Seagate Business Storage Rackmount 4-Bay NAS
Segate Business Storage Rackmount 8-Bay NAS

Download Finder

 6/15/2016

Explore security insights on our blog.

Dive into Seagate security-focused articles, where we share the latest trends, best practices, and expert insights to help safeguard your data. Stay updated on the evolving landscape of product security, vulnerabilities, and solutions designed to keep your information protected.

Our certifications and partnerships.

Seagate stays up to date on the latest industry security standards. These are the certifications Seagate has attained for its products.

Seagate certifications.

Seagate demonstrates a steadfast commitment to data sanitization, cryptographic protection and supply chain integrity through compliance with the following standards.

Data sanitization.

Seagate follows rigorous data sanitization practices to protect customer data on used drives and systems. Our certified software erasure tools and processes meet the PURGE level of the IEEE 2883 Standard for Sanitizing Storage.

We partner with the best.

We collaborate with organizations across the industry to share knowledge while also giving back to the community.