Western Digital My Cloud Mirror Gen2 Firmware 2.31.174

CPE Details

Western Digital My Cloud Mirror Gen2 Firmware 2.31.174
2.31.174
2019-05-28
10h59 +00:00
2021-05-28
15h00 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:o:westerndigital:my_cloud_mirror_gen2_firmware:2.31.174:*:*:*:*:*:*:*

Informations

Vendor

westerndigital

Product

my_cloud_mirror_gen2_firmware

Version

2.31.174

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-9949 2019-05-23 11h22 +00:00 Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows arbitrary file write by abusing symlinks. Specifically, this occurs by uploading a tar archive that contains a symbolic link, then uploading another archive that writes a file to the link using the "cgi_untar" command. Other commands might also be susceptible. Code can be executed because the "name" parameter passed to the cgi_unzip command is not sanitized.
8.8
Haute