Western data (Western Digital) wide network of welcome My Cloud series is add memory (NAS) equipment, exposed to the sun recently gave a serious safe flaw, bring about aggressor to be able to visit the content in equipment completely. Researcher Remco Vermeulen just shared Holand safety to concern this issue " the prerogative promotes attack the report " , another person of the same trade also expressed to disclose the detailed information that other atttacks already, but several heretofore did not give out on the west firmware is newer.
Remco Vermeulen points out: Identity test and verify bypasses flaw allows aggressor to win administrator limits of authority before entry equipment, they need to found retrorse Shell only, can visit the user file on driver.
If equipment is proprietary,had enabled long-range visit, so in face Internet (Internet) also put in this flaw on long-range join.
Regard a well-known NAS as equipment, western the My Cloud series of data is ascended because of safe problem frequently report end. The person that flaw is used confirmed this be related is solid again, weigh its also to number reported same hole on the west, even record whole process.
Before distributing news dispatches, several engineers group gave out to respond to eventually on the west, the problem is solved in stating they will be updated in periodic firmware, suggest client and supportive group get in touch.
WD My Cloud Security Flaw (Via)
Number is on the west in rich guest article exposure, the equipment of a lot of use Dashboard Cloud Access is atttacked easily still, include My Cloud EX2, EX4, Mirror, PR2100, PR4100 to wait.