ZDI-CAN-19745: ZDI-23-1052: Western Digital MyCloud PR4100 Logger Class Command Injection Remote Code Execution Vulnerability
Published Aug 9, 2023
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of the Western Digital MyCloud PR4100 NAS device. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Western Digital MyCloud PR4100
Event History
Aug 9, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19745?
The severity of ZDI-CAN-19745 is critical due to the ability of authenticated attackers to execute arbitrary code.
2
How do I fix ZDI-CAN-19745?
To fix ZDI-CAN-19745, update the Western Digital MyCloud PR4100 NAS device to the latest firmware version provided by Western Digital.
3
Who is affected by ZDI-CAN-19745?
Users of the Western Digital MyCloud PR4100 NAS device are affected by ZDI-CAN-19745.
4
What type of attack does ZDI-CAN-19745 facilitate?
ZDI-CAN-19745 facilitates network-adjacent attacks that allow for arbitrary code execution.
5
Is authentication required to exploit ZDI-CAN-19745?
Yes, authentication is required to exploit the ZDI-CAN-19745 vulnerability.