CVE-2016-10107: Command Injection
Published Jan 3, 2017
·Updated
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
Affected Software
1 affected component
Western Digital MyCloud NAS=2.11.142
Event History
Jan 3, 2017
CVE Published
via MITRE·06:34 AM
Data Sourced
via MITRE·06:34 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10107?
CVE-2016-10107 is classified as a high severity vulnerability due to the potential for unauthenticated remote command execution as root.
2
How do I fix CVE-2016-10107?
To mitigate CVE-2016-10107, it is recommended to upgrade to a version of Western Digital MyCloud NAS that is not affected by this vulnerability.
3
What systems are affected by CVE-2016-10107?
CVE-2016-10107 affects the Western Digital MyCloud NAS version 2.11.142.
4
Can CVE-2016-10107 be exploited remotely?
Yes, CVE-2016-10107 can be exploited remotely due to its unauthenticated nature.
5
What type of attack is possible with CVE-2016-10107?
CVE-2016-10107 allows for remote command injection, enabling attackers to execute commands as the root user.