Description
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.
Published: 2024-09-27
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-19766 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00105}

epss

{'score': 0.00114}


Fri, 27 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Westerndigital
Westerndigital my Cloud Dl2100 Firmware
Westerndigital my Cloud Dl4100 Firmware
Westerndigital my Cloud Ex2100 Firmware
Westerndigital my Cloud Ex2 Ultra Firmware
Westerndigital my Cloud Ex4100 Firmware
Westerndigital my Cloud Firmware
Westerndigital my Cloud Mirror G2 Firmware
Westerndigital my Cloud Pr2100 Firmware
Westerndigital my Cloud Pr4100 Firmware
Westerndigital wd Cloud Firmware
CPEs cpe:2.3:o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_mirror_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:wd_cloud_firmware:*:*:*:*:*:*:*:*
Vendors & Products Westerndigital
Westerndigital my Cloud Dl2100 Firmware
Westerndigital my Cloud Dl4100 Firmware
Westerndigital my Cloud Ex2100 Firmware
Westerndigital my Cloud Ex2 Ultra Firmware
Westerndigital my Cloud Ex4100 Firmware
Westerndigital my Cloud Firmware
Westerndigital my Cloud Mirror G2 Firmware
Westerndigital my Cloud Pr2100 Firmware
Westerndigital my Cloud Pr4100 Firmware
Westerndigital wd Cloud Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
Description Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102.
Title Unchecked buffer in Dynamic DNS client
Weaknesses CWE-119
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Westerndigital My Cloud Dl2100 Firmware My Cloud Dl4100 Firmware My Cloud Ex2100 Firmware My Cloud Ex2 Ultra Firmware My Cloud Ex4100 Firmware My Cloud Firmware My Cloud Mirror G2 Firmware My Cloud Pr2100 Firmware My Cloud Pr4100 Firmware Wd Cloud Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2024-09-27T18:36:19.698Z

Reserved: 2024-01-05T18:43:18.488Z

Link: CVE-2024-22170

cve-icon Vulnrichment

Updated: 2024-09-27T18:36:00.403Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-27T17:15:12.143

Modified: 2024-09-30T12:45:57.823

Link: CVE-2024-22170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses