Re: Potential Security Vulnerabilities with My Cloud Personal Cloud Systems

http://community.wd.com/t5/My-Cloud/Potential-Security-Vulnerabilities-with-My-Cloud-Personal-Cloud/td-p/898578

I hope this marks a new attitude to security issues on WD’s part. I look forward to the more collaborative problem-solving, and keeping Users informed of identified security vulnerabilities, so they can make an informed choice on whether the level of risk is acceptable.

Previous security concerns have met with silence.

http://community.wd.com/t5/My-Cloud/Trying-to-pretend-security-vulnerabilites-don-t-exist-won-t-make/m-p/898190/highlight/true#M40151

http://community.wd.com/t5/My-Cloud/Firmware-update-resets-all-setting/m-p/895778/highlight/true#M39667

http://community.wd.com/t5/My-Cloud/Reporting-security-vulnerabilities/m-p/895777/highlight/true#M39666

http://community.wd.com/t5/My-Cloud/Security-Bugs-in-MyCloud/m-p/868373/highlight/true#M33008

http://community.wd.com/t5/My-Cloud/My-ISP-reported-an-issue-with-My-Cloud/m-p/867041/highlight/true#M32656

http://community.wd.com/t5/My-Cloud/announcement-of-forthcoming-release-of-OpenSSL-on-19th-march-1-0/m-p/864575/highlight/true#M31945

http://community.wd.com/t5/My-Cloud/a-fix-is-in-the-making-for-these-vulnerabilities/m-p/860968/highlight/true#M31039

http://community.wd.com/t5/My-Cloud/Samba-vulnerability-CVE-2015-0240/m-p/859273/highlight/true#M30617

http://community.wd.com/t5/My-Cloud/GHOST-vulnerability-CVE-2015-0235/m-p/847051/highlight/true#M29024

http://community.wd.com/t5/My-Cloud/Version-of-Samba-in-mycloud-vulnerable-to-CVE-2014-3560/m-p/845621/highlight/true#M28693

http://community.wd.com/t5/My-Cloud/Product-Security-Contact/m-p/845359/highlight/true#M28640

I did some checking into the threads you posted.  In some of the threads users were simply posting questions and concerns.  As for the actual vulnerabilities brought up in the threads, we have either already fixed them or will shortly. The vulnerabilities we have fixed can be found listed in the firmware release notes.  

I want to reiterate, however, that we do take security issues seriously, and we do work towards making our products as secure as possible. So, if an issue arises, you can rest assured that we will jump on it right away.  Moreover, we have been notifying users when we’ve identified legitimate security issues.  I know because I’m the one that posts them in the forums.  

Furthermore, and I’m not sure how aware users are of this, but WD has already become very proactive in soliciting help from users when product issues arise.  We contact the users, usually within a day or so, to get as much information as we can to correctly identify and replicate the issue on our test products.  

Finally, what you or others may perceive as silence, is simply us working with the affected users behind the scenes investigating the issue.  If it turns out to be a real bug, there is nothing more that can be done until it is fixed in another firmware update, hence the apparent silence.  What we have started doing more of is posting what has been fixed in a firmware update.  

Hopefully, this helps to clear things up a bit.

1 Like

Cross posting this link from another post in another thread.

An explanation of one of the vulnerabilities previously discussed.

Command Injection in the WD My Cloud NAS

Prerequisite Information

The command injection and CSRF vulnerabilities were discovered in firmware versions _ 04.01.03-421 _ and _ 04.01.04-422 _, with the latter being the most current version as of September 11th 2015. Previous versions may be affected as well as other WD NAS products.

Mitigation

What can the average user of the WD My Cloud and other products to do reduce the likelihood of becoming a victim of this attack? The surest way to resolve these exploits is to ensure that your WD My Cloud or any other product you own is updated to the latest firmware. This can be done by logging into your device and checking the availability of updates. However, not all devices will have an update available until September 21st 2015. So until your device is updated the following strategies can help reduce the likelihood of a successful attack:

  1. Never click on links or download file attachments in e-mails or anywhere on the Internet from people or sources you do not know or trust. And even if you do trust them, verify the authenticity of the request.
  2. Never submit credentials without first verifying the authenticity of the request. Who is asking? Why are they asking? Etc.
  3. Disable WebRTC in your browsers. In FireFox this can be done with the Disable WebRTC plugin. In Chrome use the WebRTC Block plugin.
  4. Restrict access to the My Cloud device to only trusted users that need access to it. Any authorized user of this device with enough technical knowledge can gain remote access to every file.
  5. Disable remote access to the device if it is not needed.
  6. Place the WD My Cloud on a separate subnet away from client machines.