PT-2017-3361 · Western Digital · Western Digital Mycloud Pr4100

Zenofex

·

Published

2017-12-12

·

Updated

2019-05-28

·

CVE-2017-17560

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Western Digital MyCloud PR4100 version 2.30.172
Description An issue in the web administration component allows for multipart upload functionality to be accessible without authentication. This is specifically related to the "/web/jquery/uploader/multi uploadify.php" endpoint, which can be used to place a file anywhere on the device's file system. As a result, an attacker can upload a PHP shell onto the device and obtain arbitrary code execution as root. The vulnerability is related to deficiencies in the authentication procedure of the web interface.
Recommendations For Western Digital MyCloud PR4100 version 2.30.172, as a temporary workaround, consider disabling access to the "/web/jquery/uploader/multi uploadify.php" endpoint until a patch is available. Restricting access to this endpoint can minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00132
CVE-2017-17560

Affected Products

Western Digital Mycloud Pr4100