Western.Digital.MyCloud.Login.Security.Bypass

description-logoDescription

This indicates detection of a Security Bypass vulnerability in MyCloud Devices.
The vulnerability is due to an error in the vulnerable application when handling a maliciously crafted request. A remote attacker may be able exploit this to by bypass authentication, leading to further attacks.

affected-products-logoAffected Products

My Cloud
My Cloud Gen 2
My Cloud Mirror
My Cloud PR2100
My Cloud PR4100
My Cloud EX2 Ultra
My Cloud EX2
My Cloud EX4
My Cloud EX2100
My Cloud EX4100
My Cloud DL2100
My Cloud DL4100

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the most recent upgrade or patch from the vendor.
http://support.wdc.com/downloads.aspx?g=911&lang=en#firmware

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)