Vulnerability Name: | CVE-2019-9951 (CCN-160101) | ||||||||||||
Assigned: | 2019-03-27 | ||||||||||||
Published: | 2019-03-27 | ||||||||||||
Updated: | 2019-05-28 | ||||||||||||
Summary: | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage. | ||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-434 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-9951 Source: MISC Type: UNKNOWN https://bnbdr.github.io/posts/wd/ Source: CCN Type: WD Community Web site New Release - My Cloud Firmware Versions 2.31.174 Source: CONFIRM Type: Release Notes, Third Party Advisory https://community.wd.com/t/new-release-my-cloud-firmware-versions-2-31-174-3-26-19/235932 Source: XF Type: UNKNOWN wd-cve20199951-file-upload(160101) Source: MISC Type: UNKNOWN https://github.com/bnbdr/wd-rce/ Source: CONFIRM Type: Third Party Advisory https://support.wdc.com/downloads.aspx?g=2702&lang=en | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration 6: Configuration 7: Configuration 8: Configuration 9: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |