CVE-2017-17560: Critical severity WesternDigital My Cloud Pr4100 Firmware vulnerability
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multiuploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-17560?
CVE-2017-17560 is a vulnerability that affects Western Digital MyCloud PR4100 2.30.172 devices, allowing unauthorized users to upload files to any location on the device's file system.
How severe is CVE-2017-17560?
CVE-2017-17560 has a severity score of 9.8 out of 10, indicating a critical vulnerability.
How can an attacker exploit CVE-2017-17560?
An attacker can exploit CVE-2017-17560 by accessing the /web/jquery/uploader/multi_uploadify.php component of the device's web administration without authentication and uploading a file to any location on the device's file system.
Are all versions of Western Digital MyCloud PR4100 affected by CVE-2017-17560?
No, only version 2.30.172 of Western Digital MyCloud PR4100 firmware is affected by CVE-2017-17560.
Is there a fix for CVE-2017-17560?
Yes, it is recommended to update the firmware of the affected Western Digital MyCloud PR4100 devices to a version that includes the security patch for CVE-2017-17560.