PT-2016-3231 · Western Digital · Western Digital My Cloud
Publicado
2016-12-29
·
Atualizado
2023-07-28
·
CVE-2016-10108
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Western Digital MyCloud NAS version 2.11.142
Description
The issue is related to unauthenticated remote command injection as root in the Western Digital MyCloud NAS. This occurs via a modified
arg parameter in the POST data to the "/web/google analytics.php" URL. The vulnerability is associated with a lack of data sanitization at the management level, allowing an attacker to inject arbitrary commands remotely using a specially crafted arg parameter sent via the POST method.Recommendations
For Western Digital MyCloud NAS version 2.11.142, as a temporary workaround, consider restricting access to the "/web/google analytics.php" URL to minimize the risk of exploitation. Avoid using the
arg parameter in the affected URL until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Western Digital My Cloud