First published: Thu Jun 08 2023(Updated: )
This vulnerability allows remote attackers to create and read arbitrary files on affected installations of Western Digital MyCloud PR4100 NAS devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software | Affected Version | How to fix |
---|---|---|
Western Digital My Cloud PR4100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-23-848 is critical due to remote exploitation potential and the ability to bypass authentication.
To fix ZDI-23-848, update your Western Digital MyCloud PR4100 NAS to the latest firmware provided by Western Digital.
ZDI-23-848 allows attackers to create and read arbitrary files on affected devices.
Yes, authentication is required, but the vulnerability allows for the existing authentication mechanism to be bypassed.
ZDI-23-848 affects the Western Digital MyCloud PR4100 NAS devices.