VYPR

Vendor CVEs

Westerndigital

All CVEs

82 total · sorted by risk
  • CVE-2022-22996Mar 30, 2022
    risk 0.00cvss epss 0.00

    The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the system user.

  • CVE-2022-22994Jan 28, 2022
    risk 0.00cvss epss 0.02

    A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by…

  • CVE-2022-22992Jan 28, 2022
    risk 0.00cvss epss 0.02

    A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming…

  • CVE-2022-22993Jan 28, 2022
    risk 0.00cvss epss 0.01

    A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.

  • CVE-2022-22990Jan 13, 2022
    risk 0.00cvss epss 0.02

    A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP…

  • CVE-2022-22989Jan 13, 2022
    risk 0.00cvss epss 0.01

    My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.

  • CVE-2021-35941Jun 29, 2021
    risk 0.00cvss epss 0.13

    Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

  • CVE-2021-33205Jun 11, 2021
    risk 0.00cvss epss 0.01

    Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious…

  • CVE-2021-28653Mar 18, 2021
    risk 0.00cvss epss 0.01

    The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has Secure Enclave support but lacks biometric authentication hardware.

  • CVE-2021-3310Mar 10, 2021
    risk 0.00cvss epss 0.01

    Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

  • CVE-2020-29563Dec 11, 2020
    risk 0.00cvss epss 0.03

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.

  • CVE-2020-28970Dec 1, 2020
    risk 0.00cvss epss 0.04

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by…

  • CVE-2020-28940Dec 1, 2020
    risk 0.00cvss epss 0.04

    On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.

  • CVE-2020-28971Dec 1, 2020
    risk 0.00cvss epss 0.04

    An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

  • CVE-2020-27160Oct 27, 2020
    risk 0.00cvss epss 0.05

    Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).

  • CVE-2020-12830Oct 27, 2020
    risk 0.00cvss epss 0.03

    Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.

  • CVE-2020-10951Apr 15, 2020
    risk 0.00cvss epss 0.01

    Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.

  • CVE-2019-10705Mar 10, 2020
    risk 0.00cvss epss 0.01

    Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.

  • CVE-2019-10706Mar 10, 2020
    risk 0.00cvss epss 0.00

    Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install…

  • CVE-2019-11686Mar 10, 2020
    risk 0.00cvss epss 0.00

    Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.

  • CVE-2020-8960Feb 20, 2020
    risk 0.00cvss epss 0.01

    Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.

  • CVE-2020-8990Feb 20, 2020
    risk 0.00cvss epss 0.01

    Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.

  • CVE-2020-8959Feb 19, 2020
    risk 0.00cvss epss 0.00

    Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.

  • CVE-2019-18929Nov 13, 2019
    risk 0.00cvss epss 0.03

    Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arbitrary code via a download_mgr.cgi stack-based buffer overflow.

  • CVE-2019-18930Nov 13, 2019
    risk 0.00cvss epss 0.03

    Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbitrary code via a stack-based buffer overflow. There is no size verification logic in one of functions in libscheddl.so, and download_mgr.cgi makes it possible…

  • CVE-2019-18931Nov 13, 2019
    risk 0.00cvss epss 0.02

    Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via crafted GET/POST parameters.

  • CVE-2019-13467Sep 30, 2019
    risk 0.00cvss epss 0.02

    Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. This vulnerability may allow an…

  • CVE-2019-13466Sep 30, 2019
    risk 0.00cvss epss 0.01

    Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The “generate reports” archive is protected with a hard-coded password. An application update that addresses the protection of archive encryption is available.

  • CVE-2019-9949May 23, 2019
    risk 0.00cvss epss 0.03

    Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability. The cgi-bin/webfile_mgr.cgi file allows…

  • CVE-2019-9951Apr 24, 2019
    risk 0.00cvss epss 0.02

    Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an unauthenticated file upload vulnerability. The page…

  • CVE-2019-9950Apr 24, 2019
    risk 0.00cvss epss 0.02

    Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability. The login_mgr.cgi file…

  • CVE-2014-5876Sep 11, 2014
    risk 0.00cvss epss 0.00

    The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Page 2 of 2