CVE-2018-17153 - CVE House
Back to Database
Status published Critical CVE-2018-17153

It was discovered that the Western Digital My Cloud device...

Vulnerability Description

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called "cgi_get_ipv6" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter "flag" with the value "1" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-17153

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

western digital

View all reports →

Affected Software

my cloud wdbctl0020hwt firmware, my cloud pr4100, my cloud pr2100 firmware, my cloud mirror gen 2 firmware, my cloud mirror firmware, my cloud ex4100, my cloud ex4 firmware, my cloud ex2100 firmware, my cloud ex2 ultra firmware, my cloud ex2 firmware, my cloud dl4100 firmware, my cloud dl2100
Vulnerable Versions:
0

Timeline

Official Publish: September 18th, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.