PT-2024-6527 · Western Digital · Western Digital My Cloud

Noam Moshe

·

Published

2024-08-02

·

Updated

2024-10-09

·

CVE-2024-22170

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Western Digital My Cloud versions prior to 5.29.102
Description: The issue is related to an improper restriction of operations within the bounds of a memory buffer in the Western Digital My Cloud ddns-start on Linux, allowing buffer overflow. This can enable attackers to execute arbitrary code. The vulnerability is associated with the Dynamic DNS client and can be exploited by remote attackers.
Recommendations: For versions prior to 5.29.102, update to version 5.29.102 to resolve the issue. As a temporary workaround, consider restricting access to the Dynamic DNS client to minimize the risk of exploitation. Avoid using the affected ddns-start service until the issue is resolved.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-07669
CVE-2024-22170
ZDI-24-1294

Affected Products

Western Digital My Cloud