CVE-2021-33205
Western Digital EdgeRover vulnerability analysis and mitigation

Overview

Western Digital EdgeRover before version 0.25 contained an escalation of privileges vulnerability (CVE-2021-33205) that was discovered and disclosed on June 10, 2021. The vulnerability existed in the implementation of Node.js where a low privileged user could load malicious content into directories with higher privileges (Vendor Advisory).

Technical details

The vulnerability stems from improper implementation of Node.js in EdgeRover that allowed loading modules from unauthorized paths. This implementation flaw enabled attackers to load malicious content into directories that should have required higher privileges. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 HIGH with the vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability allows an attacker to gain admin privileges and perform malicious activities including creating fake libraries and stealing user credentials. The high CVSS score indicates severe potential impacts on system confidentiality, integrity, and availability (NVD, Vendor Advisory).

Exploitability

The vulnerability requires a low-privileged user account to exploit, making it relatively accessible to attackers who have gained initial access to the system. The attack complexity is rated as low, indicating that exploitation is straightforward once the prerequisite access is obtained (NVD).

Mitigation and workarounds

Western Digital addressed this vulnerability in EdgeRover version 0.25 released on May 20, 2021. The fix includes correcting the load-modules path and disabling the loading of files from external locations where less privileged users could have access. Users should upgrade to version 0.25 or later to mitigate this vulnerability (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related Western Digital EdgeRover vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-22988CRITICAL9.1
  • Western Digital EdgeRover logoWestern Digital EdgeRover
  • cpe:2.3:a:westerndigital:edgerover:*:*:*:*:*:windows:*:*
NoYesJan 13, 2022
CVE-2021-33205HIGH8.8
  • Western Digital EdgeRover logoWestern Digital EdgeRover
  • cpe:2.3:a:westerndigital:edgerover:*:*:*:*:*:windows:*:*
NoYesJun 11, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management