Skip to main content

Western Digital My Cloud Zero-Day Release

Multiple Western Digital My Cloud products have been found to contain vulnerabilities which could allow a full compromise of the device by a remote unauthenticated actor.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Multiple Western Digital My Cloud products have been found to contain vulnerabilities which could allow a full compromise of the device by a remote unauthenticated actor.

Threat details

Research shows that a firmware vulnerability can be completely bypassed allowing an unauthenticated user to gain privileged access. The vulnerability has been identified as a programming error found in the safety function code. The attacker would be able to take advantage of the bad code by adding additional arguments modifying the login state of the user enabling for a full login bypass.

Once the privileged access has been achieved by the actor, further vulnerabilities can be targeted. A large number of common interface gateway scripts have no protection in place to prevent malicious intent. This opens the possibility for the actor to inject commands for execution at root level privileges.

A successful attack would pose a serious risk of wide spread compromise, with further potential of being joined into botnets, as well as the risk to facilitate access to devices within the


Remediation steps

Type Step
  • Ensure patches are applied once released by Western Digital.

Last edited: 17 February 2020 11:41 am