First published: Wed Apr 24 2019(Updated: )
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Western Digital My Cloud Mirror Gen 2 Firmware | <2.31.174 | |
Western Digital My Cloud Mirror Gen 2 | ||
Western Digital My Cloud EX2 Ultra firmware | <2.31.174 | |
Western Digital My Cloud EX2 Ultra | ||
Western Digital My Cloud Ex2100 Firmware | <2.31.174 | |
Western Digital My Cloud Ex2100 | ||
Western Digital My Cloud Ex4100 | <2.31.174 | |
Western Digital My Cloud Ex4100 | ||
Western Digital My Cloud Dl2100 | <2.31.174 | |
Western Digital My Cloud Dl2100 | ||
Western Digital My Cloud Dl4100 Firmware | <2.31.174 | |
Western Digital My Cloud Dl4100 | ||
Western Digital My Cloud Pr2100 Firmware | <2.31.174 | |
Western Digital My Cloud Pr2100 | ||
Western Digital My Cloud Pr4100 | <2.31.174 | |
Western Digital My Cloud Pr4100 | ||
Western Digital My Cloud Firmware | <2.31.174 | |
Western Digital My Cloud |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Western Digital My Cloud firmware is CVE-2019-9951.
The severity of CVE-2019-9951 is critical with a severity value of 9.8.
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100, and My Cloud PR4100 firmware before 2.31.174 are affected.
The vulnerability in Western Digital My Cloud firmware is an unauthenticated file upload vulnerability.
To fix CVE-2019-9951, update the firmware to version 2.31.174 or later.