Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2019-9951

9.8 · CRITICAL
Published Apr 24, 2019 western_digital CWE-434 EPSS 1.68% (75th pctl)

Overview

CVE-2019-9951 is a critical-severity vulnerability affecting western_digital my_cloud_mirror_gen_2_firmware. It was published on April 24, 2019 and has a CVSS 3.0 base score of 9.8 (CRITICAL).

This vulnerability has a CVSS 3.0 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page web/jquery/uploader/uploadify.php can be accessed without any credentials, and allows uploading arbitrary files to any location on the attached storage.

Remediation

Check the references section for vendor advisories and patches from western_digital. Update my_cloud_mirror_gen_2_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
western_digital my_cloud_mirror_gen_2_firmware >= 0, < 2.31.174 Affected
western_digital my_cloud_ex2_ultra_firmware >= 0, < 2.31.174 Affected
western_digital my_cloud_ex2100_firmware >= 0, < 2.31.174 Affected
western_digital my_cloud_ex4100 >= 0, < 2.31.174 Affected
western_digital my_cloud_dl2100 >= 0, < 2.31.174 Affected
western_digital my_cloud_dl4100_firmware >= 0, < 2.31.174 Affected
western_digital my_cloud_pr2100_firmware >= 0, < 2.31.174 Affected
western_digital my_cloud_pr4100 >= 0, < 2.31.174 Affected
western_digital my_cloud_firmware >= 0, < 2.31.174 Affected

Frequently Asked Questions

What is CVE-2019-9951?

CVE-2019-9951 is a critical-severity vulnerability affecting western_digital my_cloud_mirror_gen_2_firmware. It was published on April 24, 2019 and has a CVSS 3.0 base score of 9.8 (CRITICAL).

How severe is CVE-2019-9951?

This vulnerability has a CVSS 3.0 base score of 9.8, rated CRITICAL. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2019-9951?

Check the references section for vendor advisories and patches from western_digital. Update my_cloud_mirror_gen_2_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2019-9951?

CyberStrike's AI-powered security agents can automatically detect CVE-2019-9951 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.