PT-2021-7663 · Western Digital · Western Digital My Cloud

Pedro Ribeiro

+1

·

Published

2021-07-02

·

Updated

2023-08-08

·

CVE-2021-36225

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud devices before OS5
Description The issue allows REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation. This can potentially lead to the execution of arbitrary code by a remote attacker. The vulnerability is related to the implementation of the Western Digital MyCloud PR4100 network storage device's software interface, which is associated with unrestricted uploads of dangerous file types.
Recommendations For Western Digital My Cloud devices before OS5, consider disabling REST API access for low-privileged accounts until a patch is available. Restrict access to API commands for firmware uploads and installation to minimize the risk of exploitation. Avoid using the API for firmware updates until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Improper Access Control

Unrestricted File Upload

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01117
CVE-2021-36225

Affected Products

Western Digital My Cloud