PT-2023-3460 · Western Digital · My Cloud Os

Arvind S Raj

+1

·

Published

2023-01-06

·

Updated

2024-09-05

·

CVE-2023-22816

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions My Cloud OS 5 versions prior to 5.26.300
Description The issue is related to a lack of data cleaning measures at the management level in My Cloud OS, which can be exploited by a remote attacker to execute arbitrary commands. Specifically, it is a post-authentication remote command injection vulnerability in a CGI file that could allow an attacker to build files with redirects and execute larger payloads.
Recommendations For My Cloud OS 5 versions prior to 5.26.300, update to version 5.26.300 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable CGI file until a patch is applied. Avoid using the vulnerable CGI file in the affected API endpoint until the issue is resolved.

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-03646
CVE-2023-22816

Affected Products

My Cloud Os