Lucene search

K
zdi@_s_n_t of @pentestltdZDI-24-088
HistoryFeb 06, 2024 - 12:00 a.m.

(Pwn2Own) Western Digital MyCloud PR4100 RESTSDK Uncontrolled Resource Consumption Denial-of-Service Vulnerability

2024-02-0600:00:00
@_s_n_t of @pentestltd
www.zerodayinitiative.com
7
pwn2own
western digital mycloud pr4100
remote attackers
denial-of-service vulnerability
restsdk server
uncontrolled resource consumption
attack exploitation

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

26.9%

This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Western Digital MyCloud PR4100 NAS devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RESTSDK server. The issue results from uncontrolled resource consumption. An attacker can leverage this vulnerability to create a denial-of-service condition on the device.

AI Score

6.9

Confidence

High

EPSS

0.001

Percentile

26.9%