Vulnerabilities > Westerndigital > MY Cloud OS > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-07-01 CVE-2023-22814 Authentication Bypass by Spoofing vulnerability in Westerndigital MY Cloud OS
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
network
low complexity
westerndigital CWE-290
critical
9.8
2023-05-10 CVE-2022-29841 OS Command Injection vulnerability in Westerndigital MY Cloud OS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data.
network
low complexity
westerndigital CWE-78
critical
9.8
2023-05-10 CVE-2022-29842 Command Injection vulnerability in Westerndigital MY Cloud OS
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
network
low complexity
westerndigital CWE-77
critical
9.8
2023-02-06 CVE-2021-36226 Improper Verification of Cryptographic Signature vulnerability in Westerndigital MY Cloud OS
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
network
low complexity
westerndigital CWE-347
critical
9.8
2023-02-06 CVE-2021-36224 Use of Hard-coded Credentials vulnerability in Westerndigital MY Cloud OS
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
network
low complexity
westerndigital CWE-798
critical
9.8
2022-01-28 CVE-2022-22992 Improper Encoding or Escaping of Output vulnerability in Westerndigital MY Cloud OS
A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device.
network
low complexity
westerndigital CWE-116
critical
9.8
2022-01-13 CVE-2022-22989 Out-of-bounds Write vulnerability in Westerndigital MY Cloud OS
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network.
network
low complexity
westerndigital CWE-787
critical
9.8