PT-2019-19953 · Western Digital · Western Digital My Cloud+8

Bnbdrwd

·

Published

2019-05-23

·

Updated

2019-05-29

·

CVE-2019-9949

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 versions prior to 2.31.183
Description The issue allows for code execution as root, starting from a low-privilege user session. This occurs due to the cgi-bin/webfile mgr.cgi file permitting arbitrary file write by exploiting symlinks. The vulnerability can be triggered by uploading a tar archive containing a symbolic link, followed by uploading another archive that writes a file to the link using the cgi untar command. The name parameter passed to the cgi unzip command is not sanitized, leading to code execution.
Recommendations For Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 versions prior to 2.31.183, update to firmware version 2.31.183 or later to resolve the issue. As a temporary workaround, consider restricting access to the cgi-bin/webfile mgr.cgi file and the cgi untar command to minimize the risk of exploitation. Avoid using the name parameter in the cgi unzip command until the issue is resolved.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9949

Affected Products

Dl2100
Dl4100
Ex2 Ultra
Ex2100
Ex4100
Mirror Gen2
Pr2100
Pr4100
Western Digital My Cloud