PT-2019-19954 · Western Digital · My Cloud Ex2100+8

Bnbdrwd

·

Publicado

2019-04-24

·

Atualizado

2020-08-24

·

CVE-2019-9950

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 versions prior to 2.31.174
Description The issue allows for an authentication bypass. It is related to the login mgr.cgi file, which checks credentials against /etc/shadow. However, the nobody account has a default empty password. This allows an attacker to access the control panel API as a low-privilege logged-in user, modify the My Cloud EX2 Ultra web page source code, and obtain access to the My Cloud as a non-Admin My Cloud device user.
Recommendations For versions prior to 2.31.174, update the firmware to version 2.31.174 or later to resolve the issue. As a temporary workaround, consider changing the default empty password of the nobody account to prevent unauthorized access. Restrict access to the control panel API to minimize the risk of exploitation. Avoid using the default nobody account for accessing the control panel API until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-9950

Produtos afetados

My Cloud
My Cloud Dl2100
My Cloud Dl4100
My Cloud Ex2 Ultra
My Cloud Ex2100
My Cloud Ex4100
My Cloud Mirror Gen2
My Cloud Pr2100
My Cloud Pr4100