ZDI-CAN-12465: (Pwn2Own) Western Digital MyCloud PR4100 nasAdmin Incorrect Authorization Authentication Bypass Vulnerability
This vulnerability allows remote attackers to bypass authentication on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability. The specific flaw exists within the modrewrite module. The issue results from the way the software parses URLs to make authorization decisions. An attacker can leverage this vulnerability to bypass authentication on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-12465?
The severity of ZDI-CAN-12465 is classified as critical due to the potential for remote exploitation.
What products are affected by ZDI-CAN-12465?
The affected product for ZDI-CAN-12465 is the Western Digital MyCloud PR4100.
How do I fix ZDI-CAN-12465?
To fix ZDI-CAN-12465, update the firmware of your Western Digital MyCloud PR4100 to the latest version that addresses this vulnerability.
Can ZDI-CAN-12465 be exploited without authentication?
Yes, ZDI-CAN-12465 can be exploited without authentication, allowing attackers to bypass security measures.
What type of vulnerability is ZDI-CAN-12465?
ZDI-CAN-12465 is an authentication bypass vulnerability that affects the mod_rewrite module.