New Release - My Cloud Firmware Versions 2.31.163 (1/8/19)


#1

WD is happy to announce the release of My Cloud Firmware 2.31.163 for manual download at [https://support.wdc.com/downloads.aspx?g=910&lang=en) for the following My Cloud products.

· My Cloud
· My Cloud Mirror Gen2
· My Cloud EX2 Ultra
· My Cloud EX2100
· My Cloud EX4100
· My Cloud DL2100
· My Cloud DL4100
· My Cloud PR2100
· My Cloud PR4100

2.31.163 Release Notes

Security Fixes

  • Added brute force attack mitigation.
  • Removed non-production testing information.

Components Updated

  • Rsync – v3.0.

Other Bug Fixes

  • Added warnings when enabling remote dashboard.

2.31.149 Release Notes

Security Fixes

• Resolved multiple command injection vulnerabilities including CVE-2016-10108 and CVE 2016-10107.
• Resolved multiple cross site request forgery (CSRF) vulnerabilities.
• Resolved a Linux kernel Dirty Cow vulnerability (CVE-2016-5195).
• Resolved multiple denial-of-service vulnerabilities.
• Improved security by disabling SSH shadow information.
• Resolved a buffer overflow issue that could lead to unauthenticated access.
• Resolved a click-jacking vulnerability in the web interface.
• Resolved multiple security issues in the Webfile viewer on-device app.
• Improved the security of volume mount options.
• Resolved multiple security issues in the EULA onboarding flow.
• Resolved leakage of debug messages in the web interface.
• Improved credential handling for the remote MyCloud-to-MyCloud backup feature.
• Improved credential handling for upload-logs-to-support option.

Components Updated

• Apache -v2.4.34
• PHP -v5.4.45
• OpenSSH -v7.5p1
• OpenSSL -v1.0.1u
• libupnp -v1.6.25 (CVE-2012-5958)
• jQuery -v3.3.1 (CVE-2010-5312)

Other Bug Fixes

• Resolved high CPU utilization with ufraw-batch process.
• Improved remote host port handling


#2

#3

#4

#5

An updated kernel version would be nice…


#6

Any plans to provide such throughout security fixes for the MyCloud Mirror 1st gen (2.11.x FW) as well?

Those 2.11.x FW version is e.g. still vulnerable for the libupnp vulnerability posted few years ago:


New firmware 2.31.149 for Cloud EX2?
#7

WD My Cloud App doesn’t connect with the cloud anymore ? App find the device and show correct IP adress, but then get an error after update for 2.31.149ver.


#8

@blk Support questions probably doesn’t belong into a firmware release thread.


#9

I have the same problem after update to 2.31.149 firmware version.
My Cloud App (windows version) does not connect anymore to the NAS from remote.
PLAESE SOMEONE CAN HELP ME ???!!!
Thank you in advance


#10

Super les mise a jour quand le my cloud marche plus …


#11

Great that security fixes were done.

Now how about a basic “reboot” after updating so the box PR4100 doesn’t just sit there saying, “SYSTEM REBOOTING” forever? I have two of these NAS boxes and both won’t automatically reboot after a firmware update or when doing a reboot from the web interface.

It reflects very poorly on WD’s quality care that I have to get to the physical box (behind a rolling rack) to manually power down the unit every time I try a soft reboot.

Best wishes,


#12

My My Cloud Mirror Gen 2 is unstable after manual upgrading to 2.31.163.

While the SAMBA file services are available, the Dashboard has been unreachable for several days now for login. The login screen (usually) appears and login proceeds to the dashboard home screen (of which I at most get the top row of buttons) but then it stops and the site becomes unresponsive.
Last night I unplugged it, let it rest until the morning, reconnected and was able to login fine.
I started a USB disc backup and now after about 1 hr the same thing. Dashboard practically unreachable.

It is a 2x 4 TB RAID 1 setup with about 2 TB used. Both discs where “good” and S.M.A.R.T. did not show anything. There is , apart from the Cloud access, no services allowed: none of the optional apps is installed, all media services are disabled, really on the rock bottom. I have two external cloud users and about 9 IOS devices which can (but currently do not) access the cloud. Ah yes, external cloud access is not working from any of the devices. SMB services are doing fine though.

I am getting to the point to chuck the WD MCM into the bin.
I bought it for all the features it offered (including ZWay Server) but in the end for several years have been barely able to use it as an NAS.

It is totally incomprehensible to me how WD digital gets away with these practices.
They put out a product that does not work as advertised, for years it system software contained a backdoor entry for hacker and left sensitive data vulnerable to attack, even worse, the code that did that was stolen from a competitor who was much faster fixing the vulnerability.
Why has there not been a class action law suit against them? I would certainly sign up …
Customers must be warned about the lousiness of their products.
So, I have just placed and order for a Synology Diskstation and will go over to Amazon to write a review …

EB