PT-2024-6527 · Western Digital · Western Digital My Cloud
Noam Moshe
·
Published
2024-08-02
·
Updated
2024-10-09
·
CVE-2024-22170
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Western Digital My Cloud versions prior to 5.29.102
Description:
The issue is related to an improper restriction of operations within the bounds of a memory buffer in the Western Digital My Cloud ddns-start on Linux, allowing buffer overflow. This can enable attackers to execute arbitrary code. The vulnerability is associated with the Dynamic DNS client and can be exploited by remote attackers.
Recommendations:
For versions prior to 5.29.102, update to version 5.29.102 to resolve the issue. As a temporary workaround, consider restricting access to the Dynamic DNS client to minimize the risk of exploitation. Avoid using the affected ddns-start service until the issue is resolved.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Western Digital My Cloud