Western Digital My Cloud Zero-Day Release
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Research shows that a firmware vulnerability can be completely bypassed allowing an unauthenticated user to gain privileged access. The vulnerability has been identified as a programming error found in the safety function code. The attacker would be able to take advantage of the bad code by adding additional arguments modifying the login state of the user enabling for a full login bypass.
Once the privileged access has been achieved by the actor, further vulnerabilities can be targeted. A large number of common interface gateway scripts have no protection in place to prevent malicious intent. This opens the possibility for the actor to inject commands for execution at root level privileges.
A successful attack would pose a serious risk of wide spread compromise, with further potential of being joined into botnets, as well as the risk to facilitate access to devices within the
Last edited: 17 February 2020 11:41 am