Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.113857
Category:General
Title:Western Digital My Cloud Multiple Products 5.0 < 5.21.104 Samba Vulnerability (WDC-22006)
Summary:Multiple Western Digital My Cloud products are prone to a; vulnerability in Samba.
Description:Summary:
Multiple Western Digital My Cloud products are prone to a
vulnerability in Samba.

Vulnerability Insight:
Samba is vulnerable to an out-of-bounds heap read write
vulnerability that allows remote attackers to execute arbitrary code as root on affected Samba
installations that use the VFS module vfs_fruit.

The specific flaw exists within the parsing of EA metadata when opening files in smbd. Access as
a user that has write access to a file's extended attributes is required to exploit this
vulnerability. Note that this could be a guest or unauthenticated user if such users are allowed
write access to file extended attributes.

The problem in vfs_fruit exists in the default configuration of the fruit VFS module using
fruit:metadata=netatalk or fruit:resource=file. If both options are set to different settings
than the default values, the system is not affected by the security issue.

Affected Software/OS:
Western Digital My Cloud PR2100, My Cloud PR4100, My Cloud
EX4100, My Cloud EX2 Ultra, My Cloud Mirror Gen 2, My Cloud DL2100, My Cloud DL4100, My Cloud
EX2100, My Cloud and WD Cloud with firmware versions prior to 5.21.104.

Solution:
Update to firmware version 5.21.104 or later.

CVSS Score:
9.0

CVSS Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-44142
CERT/CC vulnerability note: https://kb.cert.org/vuls/id/119678
https://kb.cert.org/vuls/id/119678
https://bugzilla.samba.org/show_bug.cgi?id=14914
https://www.samba.org/samba/security/CVE-2021-44142.html
https://security.gentoo.org/glsa/202309-06
https://www.zerodayinitiative.com/blog/2022/2/1/cve-2021-44142-details-on-a-samba-code-execution-bug-demonstrated-at-pwn2own-austin
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.