Vulnerabilities > Westerndigital

DATE CVE VULNERABILITY TITLE RISK
2020-03-10 CVE-2019-10706 Insufficiently Protected Credentials vulnerability in Westerndigital products
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest.
6.3
2020-02-20 CVE-2020-8960 Cross-site Scripting vulnerability in Westerndigital Mycloud.Com
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
4.3
2020-02-19 CVE-2020-8959 Uncontrolled Search Path Element vulnerability in Westerndigital products
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
4.4
2019-09-30 CVE-2019-13467 Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. 4.3
2019-09-30 CVE-2019-13466 Use of Hard-coded Credentials vulnerability in multiple products
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control.
network
low complexity
sandisk westerndigital CWE-798
5.0
2019-09-18 CVE-2019-16399 Use of Hard-coded Credentials vulnerability in Westerndigital WD MY Book Firmware
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials.
network
low complexity
westerndigital CWE-798
7.5
2019-06-19 CVE-2018-18472 OS Command Injection vulnerability in Westerndigital MY Book Live Firmware
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter.
network
low complexity
westerndigital CWE-78
critical
10.0
2019-05-23 CVE-2019-9949 Link Following vulnerability in Westerndigital products
Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmware 2.31.183 are affected by a code execution (as root, starting from a low-privilege user session) vulnerability.
network
low complexity
westerndigital CWE-59
critical
9.0
2019-04-24 CVE-2019-9950 Weak Password Requirements vulnerability in Westerndigital products
Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, My Cloud DL4100, My Cloud PR2100 and My Cloud PR4100 firmware before 2.31.174 is affected by an authentication bypass vulnerability.
network
low complexity
westerndigital CWE-521
7.5
2018-10-09 CVE-2018-7928 Unspecified vulnerability in Westerndigital MY Cloud
There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones.
local
low complexity
westerndigital
3.6