Vulnerabilities > Westerndigital > MY Cloud > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-08 CVE-2023-22813 Missing Authorization vulnerability in Westerndigital products
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App.
network
low complexity
westerndigital CWE-862
4.3
2018-03-30 CVE-2018-9148 Improper Authentication vulnerability in Westerndigital MY Cloud Firmware 04.05.00320
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory.
network
low complexity
westerndigital CWE-287
5.0