ZDI-23-1052: Western Digital MyCloud PR4100 Logger Class Command Injection Remote Code Execution Vulnerability
Published Aug 9, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of the Western Digital MyCloud PR4100 NAS device. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Western Digital MyCloud PR4100
Event History
Aug 9, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1052?
ZDI-23-1052 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix ZDI-23-1052?
To fix ZDI-23-1052, update the Western Digital MyCloud PR4100 NAS device to the latest firmware version provided by the vendor.
3
Who can exploit ZDI-23-1052?
Only authenticated network-adjacent attackers can exploit the ZDI-23-1052 vulnerability.
4
What type of vulnerability is ZDI-23-1052?
ZDI-23-1052 is a remote code execution vulnerability affecting the Western Digital MyCloud PR4100 NAS device.
5
Is ZDI-23-1052 being actively exploited?
As of the latest information, there are no public reports indicating active exploitation of ZDI-23-1052.