CVE-2019-9951
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.
Published:Apr 24, 2019
Last Modified:Nov 21, 2024
EPS:Apr 24, 2019
EPSS Score:0.01333
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Western Digital
Product
My Cloud
Western Digital
My Cloud
Vendor
Western Digital
Product
My Cloud Dl2100
Western Digital
My Cloud Dl2100
Vendor
Western Digital
Product
My Cloud Dl4100
Western Digital
My Cloud Dl4100
Vendor
Western Digital
Product
My Cloud Dl4100 Firmware
Western Digital
My Cloud Dl4100 Firmware
Vendor
Western Digital
Product
My Cloud Ex2100
Western Digital
My Cloud Ex2100
Vendor
Western Digital
Product
My Cloud Ex2100 Firmware
Western Digital
My Cloud Ex2100 Firmware
Vendor
Western Digital
Product
My Cloud Ex2 Ultra
Western Digital
My Cloud Ex2 Ultra
Vendor
Western Digital
Product
My Cloud Ex2 Ultra Firmware
Western Digital
My Cloud Ex2 Ultra Firmware
Vendor
Western Digital
Product
My Cloud Ex4100
Western Digital
My Cloud Ex4100
Vendor
Western Digital
Product
My Cloud Firmware
Western Digital
My Cloud Firmware
Vendor
Western Digital
Product
My Cloud Mirror Gen 2
Western Digital
My Cloud Mirror Gen 2
Vendor
Western Digital
Product
My Cloud Mirror Gen 2 Firmware
Western Digital
My Cloud Mirror Gen 2 Firmware
Vendor
Western Digital
Product
My Cloud Pr2100
Western Digital
My Cloud Pr2100
Vendor
Western Digital
Product
My Cloud Pr2100 Firmware
Western Digital
My Cloud Pr2100 Firmware
Vendor
Western Digital
Product
My Cloud Pr4100
Western Digital
My Cloud Pr4100
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
