ZDI-CAN-22537: ZDI-24-1294: Western Digital MyCloud PR4100 ddns-start Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Sep 26, 2024
·Updated
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-22170.
Affected Software
1 affected component
Western Digital MyCloud PR4100
Event History
Sep 26, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22537?
The severity of ZDI-CAN-22537 is rated at 7.5, indicating a high risk level.
2
What systems are affected by ZDI-CAN-22537?
ZDI-CAN-22537 affects Western Digital MyCloud PR4100 installations.
3
Does ZDI-CAN-22537 require authentication to exploit?
No, ZDI-CAN-22537 can be exploited without requiring authentication.
4
What type of code can be executed due to ZDI-CAN-22537?
ZDI-CAN-22537 allows network-adjacent attackers to execute arbitrary code.
5
How can I protect myself from ZDI-CAN-22537?
To protect against ZDI-CAN-22537, ensure to apply any available patches and review security configurations for the affected device.