Eblogtip.com
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions

Archives

  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • December 2022

Categories

  • News
  • Technology
  • Uncategorized
eBlogTip
  • Categories
    • News
    • Technology
    • Domains
    • Hosting
    • Promotions
  • News

Western Digital patches potentially dangerous security flaw, so update now

  • August 24, 2023
Total
0
Shares
0
0
0


Western Digital has patched a potentially dangerous flaw found in the firmware of some of its network-attached storage devices (NAS).

In a press release, Western Digital said that a cybersecurity researcher from Positive Technologies, Nikita Abramov, discovered a high-severity flaw in its NAS devices which could allow threat actors to run arbitrary code remotely, steal data, and breach confidential information. 

The flaw is tracked as CVE-2023-22815, and holds a severity score of 8.8. It was discovered in the firmware of My Cloud OS 5, v5.23.114, software used by a number of WD devices, such as My Cloud PR2100, My Cloud PR4100, My Cloud EX4100, My Cloud EX2 Ultra, My Cloud Mirror G2, and others.

Dangerous scenario

“The most dangerous scenario is a complete seizure of control over NAS. All further steps depend on the attacker’s objectives: stealing, modifying, or completely removing data, and possibly deploying malware,” commented Nikita Abramov. 

He further explained that the flaw was most likely introduced with new features that weren’t analyzed properly: “The vulnerability is likely caused by adding new functionality to NAS without proper security checks. Other similar parts of the web interface (that could be used for command injection) filtered and checked the received data, preventing cyberattacks from happening,” Abramov concluded.  

Further in the press release, WD said that there are currently more than 2,400 NAS devices available on the global network, with the majority being in Germany (460), the US (310), Italy (257), the UK (131), and South Korea (125).

To address the issue, users should install the updated My Cloud OS 5 v5.26.300 firmware on all affected devices. The full list of vulnerable endpoints can be found on this link.

NAS devices are a popular target among cybercriminals. QNAP’s NAS hardware, for example, has been targeted multiple times over the last three years. 


Source link

Total
0
Shares
Share 0
Tweet 0
Pin it 0
Previous Article
  • Technology

5 trends in VC funding for pre-seed startups

  • August 24, 2023
View Post
Next Article
  • Technology

Rocketium scales and analyzes massive marketing campaigns

  • August 24, 2023
View Post
You May Also Like
View Post
  • News

Microsoft Paint is getting its biggest upgrade in over a decade thanks to Windows Copilot

  • September 26, 2023
View Post
  • News

NFT marketplace OpenSea has been hacked, again

  • September 26, 2023
View Post
  • News

LG drops ATSC 3.0 4K tuners from its 2024 OLED TVs and Samsung or Sony could be next

  • September 26, 2023
View Post
  • News

CISOs are spending more on cybersecurity – but it might not be enough

  • September 26, 2023
View Post
  • News

iPhone 15 delays: latest delivery estimates for every model

  • September 26, 2023
View Post
  • News

Hideki Kamiya thanks fans for their support after leaving PlatinumGames and says he will keep making games

  • September 26, 2023
View Post
  • News

SAP goes all-in on AI with new Joule copilot

  • September 26, 2023
View Post
  • News

Star Wars’ Ahsoka Tano is now live in Fortnite alongside a new themed battle pass

  • September 26, 2023

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

eBlogTip.com
  • Categories

Input your search keywords and press Enter.