ZDI-24-088: (Pwn2Own) Western Digital MyCloud PR4100 RESTSDK Uncontrolled Resource Consumption Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Western Digital MyCloud PR4100 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2023-22819.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-088?
ZDI-24-088 has been assigned a CVSS rating of 5.3, indicating a medium severity vulnerability.
What devices are affected by ZDI-24-088?
The vulnerability ZDI-24-088 affects Western Digital MyCloud PR4100 NAS devices.
Is authentication required to exploit ZDI-24-088?
No, authentication is not required to exploit the ZDI-24-088 vulnerability.
What type of attack does ZDI-24-088 allow?
ZDI-24-088 allows remote attackers to create a denial-of-service condition on affected devices.
How can I remediate ZDI-24-088?
Remediation for ZDI-24-088 typically involves applying available security patches or updates from Western Digital.