Lucene search

K
nvd[email protected]NVD:CVE-2019-9950
HistoryApr 24, 2019 - 6:29 p.m.

CVE-2019-9950

2019-04-2418:29:01
CWE-521
web.nvd.nist.gov

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.2%

Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file checks credentials against /etc/shadow. However, the “nobody” account (which can be used to access the control panel API as a low-privilege logged-in user) has a default empty password, allowing an attacker to modify the My Cloud EX2 Ultra web page source code and obtain access to the My Cloud as a non-Admin My Cloud device user.

Affected configurations

NVD
Node
westerndigitalmy_cloud_firmwareRange<2.31.174
AND
westerndigitalmy_cloudMatch-
Node
westerndigitalmy_cloud_mirror_gen2_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_mirror_gen2Match-
Node
westerndigitalmy_cloud_ex2_ultra_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_ex2_ultraMatch-
Node
westerndigitalmy_cloud_ex2100_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_ex2100Match-
Node
westerndigitalmy_cloud_ex4100_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_ex4100Match-
Node
westerndigitalmy_cloud_dl2100_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_dl2100Match-
Node
westerndigitalmy_cloud_dl4100_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_dl4100Match-
Node
westerndigitalmy_cloud_pr2100_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_pr2100Match-
Node
westerndigitalmy_cloud_pr4100_firmwareRange<2.31.174
AND
westerndigitalmy_cloud_pr4100Match-

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.7 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.2%

Related for NVD:CVE-2019-9950