Lucene search

K
zdi@_s_n_t of @pentestltdZDI-24-087
HistoryFeb 06, 2024 - 12:00 a.m.

(Pwn2Own) Western Digital MyCloud PR4100 RESTSDK Server-Side Request Forgery Vulnerability

2024-02-0600:00:00
@_s_n_t of @pentestltd
www.zerodayinitiative.com
8
pwn2own
western digital mycloud
pr4100
restsdk
server-side request forgery
network-adjacent attackers
arbitrary code execution
authentication bypass
lack of uri validation
root context

7.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.4%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100 NAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RESTSDK server. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root.

7.2 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.4%

Related for ZDI-24-087