Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2018-17153

9.8 · CRITICAL
Published Sep 18, 2018 western_digital CWE-287 EPSS 86.59% (100th pctl)

Overview

CVE-2018-17153 is a critical-severity vulnerability affecting western_digital my_cloud_wdbctl0020hwt_firmware. It was published on September 18, 2018 and has a CVSS 3.0 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.0 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called "cgi_get_ipv6" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter "flag" with the value "1" is provided. Subsequent invoc

Remediation

Check the references section for vendor advisories and patches from western_digital. Update my_cloud_wdbctl0020hwt_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
western_digital my_cloud_wdbctl0020hwt_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_pr4100 >= 0, < 2.30.196 Affected
western_digital my_cloud_pr2100_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_mirror_gen_2_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_mirror_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_ex4100 >= 0, < 2.30.196 Affected
western_digital my_cloud_ex4_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_ex2100_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_ex2_ultra_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_ex2_firmware >= 0, < 2.30.196 Affected
western_digital my_cloud_dl4100_firmware >= 0, < 2.30.196 Affected

Frequently Asked Questions

What is CVE-2018-17153?

CVE-2018-17153 is a critical-severity vulnerability affecting western_digital my_cloud_wdbctl0020hwt_firmware. It was published on September 18, 2018 and has a CVSS 3.0 base score of 9.8 (CRITICAL).

How severe is CVE-2018-17153?

This vulnerability has a CVSS 3.0 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2018-17153?

Check the references section for vendor advisories and patches from western_digital. Update my_cloud_wdbctl0020hwt_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2018-17153?

CyberStrike's AI-powered security agents can automatically detect CVE-2018-17153 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.