ZDI-CAN-22440: ZDI-24-088: (Pwn2Own) Western Digital MyCloud PR4100 RESTSDK Uncontrolled Resource Consumption Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Western Digital MyCloud PR4100 NAS devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2023-22819.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22440?
The CVSS rating assigned to ZDI-CAN-22440 is 5.3, indicating a medium severity level.
What type of vulnerability is ZDI-CAN-22440?
ZDI-CAN-22440 is a denial-of-service vulnerability that can be exploited remotely without authentication.
How can ZDI-CAN-22440 be exploited?
Remote attackers can exploit ZDI-CAN-22440 to create a denial-of-service condition on affected Western Digital MyCloud PR4100 NAS devices.
What devices are affected by ZDI-CAN-22440?
The vulnerability ZDI-CAN-22440 specifically affects Western Digital MyCloud PR4100 NAS devices.
Is authentication required to exploit ZDI-CAN-22440?
No, authentication is not required to exploit the ZDI-CAN-22440 vulnerability.