First published: Mon Feb 05 2024(Updated: )
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires the attacker to already have root privileges in order to exploit this vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.5.1-104; ibi: before 9.5.1-104; My Cloud OS 5: before 5.27.161.
Credit: psirt@wdc.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Western Digital My Cloud PR4100 | ||
Western Digital My Cloud PR4100 Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud EX4100 Firmware | ||
Western Digital My Cloud EX4100 Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud EX2 Ultra Firmware | ||
Western Digital My Cloud EX2 Ultra Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud Mirror Gen 2 | ||
Western Digital My Cloud Mirror Gen 2 Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud DL2100 Firmware | ||
Western Digital My Cloud DL2100 Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud DL4100 Firmware | ||
Western Digital My Cloud DL4100 Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud EX2100 Firmware | ||
Western Digital My Cloud EX2100 Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud Glacier Firmware | ||
Western Digital My Cloud Glacier Firmware | <5.27.161 | |
All of | ||
Western Digital My Cloud Firmware | <5.27.161 | |
Western Digital My Cloud | ||
All of | ||
Western Digital My Cloud Home firmware | <9.5.1-104 | |
Western Digital My Cloud Home | ||
All of | ||
Western Digital My Cloud Home Duo Firmware | <9.5.1-104 | |
Western Digital My Cloud Home Duo | ||
All of | ||
SanDisk ibi firmware | <9.5.1-104 | |
SanDisk ibi |
For My Cloud OS 5 devices, Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification. My Cloud Home, My Cloud Home Duo and SanDisk ibi devices will be automatically updated to reflect the latest firmware version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22819 is classified as an uncontrolled resource consumption vulnerability with potential denial-of-service consequences.
To mitigate CVE-2023-22819, update the affected Western Digital My Cloud firmware to the latest version available.
CVE-2023-22819 affects Western Digital My Cloud Home, My Cloud Home Duo, and several other My Cloud devices with specific firmware versions.
Yes, CVE-2023-22819 can lead to excessive memory consumption resulting in a service outage or crash.
CVE-2023-22819 can be exploited by sending crafted requests designed to exhaust system memory.