9.8

CVE-2019-9951

Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Western DigitalMy Cloud Ex2100 Firmware Version < 2.31.174
   Western DigitalMy Cloud Ex2100 Version-
Western DigitalMy Cloud Ex4100 Version < 2.31.174
   Western DigitalMy Cloud Ex4100 Version-
Western DigitalMy Cloud Dl2100 Version < 2.31.174
   Western DigitalMy Cloud Dl2100 Version-
Western DigitalMy Cloud Dl4100 Firmware Version < 2.31.174
   Western DigitalMy Cloud Dl4100 Version-
Western DigitalMy Cloud Pr2100 Firmware Version < 2.31.174
   Western DigitalMy Cloud Pr2100 Version-
Western DigitalMy Cloud Pr4100 Version < 2.31.174
   Western DigitalMy Cloud Pr4100 Version-
Western DigitalMy Cloud Firmware Version < 2.31.174
   Western DigitalMy Cloud Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.33% 0.781
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.