CVE-2019-9951: Malicious File Upload
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Western Digital My Cloud firmware?
The vulnerability ID for the Western Digital My Cloud firmware is CVE-2019-9951.
What is the severity of CVE-2019-9951?
The severity of CVE-2019-9951 is critical with a severity value of 9.8.
Which Western Digital products are affected by CVE-2019-9951?
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100, and My Cloud PR4100 firmware before 2.31.174 are affected.
What is the vulnerability in Western Digital My Cloud firmware?
The vulnerability in Western Digital My Cloud firmware is an unauthenticated file upload vulnerability.
How do I fix CVE-2019-9951?
To fix CVE-2019-9951, update the firmware to version 2.31.174 or later.