Orbi WiFi 7 RBE973
Reply

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

jmhga44
Star

NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

My NetGear Armor is continuously detecting vulnerabilities on my Western Digital Mycloud drive even though it is not connected to the Internet (software is out of life). It doesn't seem to detect any problems on anything else I've got connected to my home network. Would anyone have any ideas on how to solve this? This might become a moot point next month when the Netgear Armor subscription runs out and I might not renew it. 

Message 1 of 10
MetsFan69
Aspirant

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

Same problem here with my WD MyCloud 6TB. Has detected vulnerabilities since day one of having Armor. I also have the latest MyCloud firmware: 5.21.10, and cloud access is disabled on MyCloud.

 

Not sure if they are false positives or are unaddressed vulnerabilities by WD.

Message 2 of 10
jmhga44
Star

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

Thanks for the response. At least I'm not the only one with this situation.

Message 3 of 10
Topology
Virtuoso

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

Perhaps NETGEAR Armor is detecting the existence of a default username/password for the WD My Cloud device, even if cloud access is disabled?

Message 4 of 10
MetsFan69
Aspirant

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

It finds >139 vulnerabilities and I'm not using default authentication

Message 5 of 10
Jeffgear
Luminary

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

A quick search on the ISC2 vulnerability database shows a few critical vulnerabilities for Western Digital Mycloud. Armor may be detecting indicators related to these vulnerabilities if present on your service. It might be worth following upon the CVEs for the vendor's mitigation guidance. DBA9B774-7AED-43A5-B982-65E1E2175365.jpeg

Message 6 of 10
jmhga44
Star

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

The vulnerabilities you show in your post seem to be for the WD MyCloud PR4100..that's not the model I have. How did you find those?

Message 7 of 10
jmhga44
Star

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

Jeffgear.. I also just found out about a firmware update for my drive to v4.06.00-111 and am applying it. I'll see what NetGear Armor shows after that gets applied.

Message 8 of 10
Jeffgear
Luminary

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

I search for WD mycloud in a vulnerability database service that the ISC InfoSec organisation provides to its subscribers. Although this is not for non members the CVE numbers can be googled for more details. As you correctly point out the ones I listed are for a different model but I suspect they may be present across their platform as is sometimes the case. I could not find anything specific to your model but if you research the CVE and vendor’s vulnerability notifications you may be able to confirm if your particular model is affected. If not, I suspect it’s an Armor false -+ve.
Message 9 of 10
Jeffgear
Luminary

Re: NetGear Armor and Western Digital NAS vulnerabilities on RAX 50

Fingers crossed it fixes the alerts. If not then I suspect a false +ve.
Message 10 of 10
Top Contributors
Discussion stats
  • 9 replies
  • 2573 views
  • 1 kudo
  • 4 in conversation
Announcements

Orbi WiFi 7