CVE-2020-28971: (Pwn2Own) Western Digital MyCloud PR4100 nasAdmin Authentication Bypass Vulnerability
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.
Other sources
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Western Digital MyCloud PR4100. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the nasAdmin service, which listens on TCP port 80 and 443 by default. The issue results from incorrect string matching logic when accessing protected pages. An attacker can leverage this vulnerability to execute arbitrary code in the context of root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-28971?
CVE-2020-28971 is a vulnerability that allows network-adjacent attackers to bypass authentication on affected installations of Western Digital MyCloud PR4100.
How severe is CVE-2020-28971?
CVE-2020-28971 has a severity rating of 9.8, indicating a critical vulnerability.
What software versions are affected by CVE-2020-28971?
The affected software version is Western Digital MyCloud OS 5 up to version 5.06.115.
How can the authentication bypass be exploited?
The existing authentication mechanism can be bypassed.
Is there a fix available for CVE-2020-28971?
Yes, Western Digital has released firmware version 5.06.115 to address the vulnerability.