S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 23, 2024

CVE-2018-17153 Scanner

CVE-2018-17153 scanner - Authentication Bypass vulnerability in Western Digital MyCloud NAS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-17153
9.8
CVSS

It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authenticate as an admin user without needing to provide a password, thereby gaining full control of the device. (Whenever an admin logs into My Cloud, a server-side session is created that is bound to the user's IP address. After the session is created, it is possible to call authenticated CGI modules by sending the cookie username=admin in the HTTP request. The invoked CGI will check if a valid session is present and bound to the user's IP address.) It was found that it is possible for an unauthenticated attacker to create a valid session without a login. The network_mgr.cgi CGI module contains a command called "cgi_get_ipv6" that starts an admin session -- tied to the IP address of the user making the request -- if the additional parameter "flag" with the value "1" is provided. Subsequent invocation of commands that would normally require admin privileges now succeed if an attacker sets the username=admin cookie.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

The Western Digital MyCloud NAS is a popular network-attached storage device used for storing and sharing files amongst multiple devices within a network. It is designed for personal or small business use, with features such as data backup, media streaming, and remote access. 

However, the MyCloud device before version 2.30.196 was discovered to have an authentication bypass vulnerability, identified as CVE-2018-17153. This vulnerability allows a remote, unauthenticated attacker to gain complete access to the device, with the capability to authenticate as an admin user without providing a password. 

When exploited, this vulnerability can lead to a multitude of disastrous outcomes for the device owner. An attacker could potentially steal, modify, or delete sensitive files on the device, or even launch further attacks on other devices within the same network. Additionally, an attacker could use the device as a staging ground for conducting botnet attacks, resulting in significant security and performance issues. 

At s4e.io, our pro features allow users to quickly and easily scan their digital assets for known vulnerabilities. By utilizing our platform, users can stay informed and proactively protect their devices against critical weaknesses, such as the CVE-2018-17153 vulnerability affecting the MyCloud NAS. Stay ahead of potential threats and sign up for our pro account today.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are recommended to update their MyCloud device firmware to the latest version, which patches the flaw. Additionally, users can take the following precautions:

  • Ensure the MyCloud device is not directly accessible from the internet
  • Restrict network access to the device only to trusted devices and IPs
  • Implement strong and unique passwords for all users accessing the device
  • Regularly monitor logs and network traffic for any suspicious activity
  • Consider using a third-party security scanning tool or service to identify vulnerabilities pre-emptively

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.