PT-2019-19953 · Western Digital · Western Digital My Cloud+8
Bnbdrwd
·
Published
2019-05-23
·
Updated
2019-05-29
·
CVE-2019-9949
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 versions prior to 2.31.183
Description
The issue allows for code execution as root, starting from a low-privilege user session. This occurs due to the
cgi-bin/webfile mgr.cgi file permitting arbitrary file write by exploiting symlinks. The vulnerability can be triggered by uploading a tar archive containing a symbolic link, followed by uploading another archive that writes a file to the link using the cgi untar command. The name parameter passed to the cgi unzip command is not sanitized, leading to code execution.Recommendations
For Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 versions prior to 2.31.183, update to firmware version 2.31.183 or later to resolve the issue. As a temporary workaround, consider restricting access to the
cgi-bin/webfile mgr.cgi file and the cgi untar command to minimize the risk of exploitation. Avoid using the name parameter in the cgi unzip command until the issue is resolved.Exploit
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dl2100
Dl4100
Ex2 Ultra
Ex2100
Ex4100
Mirror Gen2
Pr2100
Pr4100
Western Digital My Cloud