PT-2019-19955 · Western Digital · My Cloud Ex2100+8
Bnbdrwd
·
Publicado
2019-04-24
·
Atualizado
2019-05-28
·
CVE-2019-9951
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware versions prior to 2.31.174
Description
The issue allows for an unauthenticated file upload, enabling the upload of arbitrary files to any location on the attached storage. This is possible through access to the "web/jquery/uploader/uploadify.php" page without requiring any credentials.
Recommendations
For Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware versions prior to 2.31.174, update the firmware to version 2.31.174 or later to resolve the issue. As a temporary workaround, consider restricting access to the "web/jquery/uploader/uploadify.php" page to prevent unauthenticated file uploads.
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
My Cloud
My Cloud Dl2100
My Cloud Dl4100
My Cloud Ex2 Ultra
My Cloud Ex2100
My Cloud Ex4100
My Cloud Mirror Gen2
My Cloud Pr2100
My Cloud Pr4100