Vulnerabilities > Westerndigital
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-10-27 | CVE-2020-12830 | Out-of-bounds Write vulnerability in Westerndigital MY Cloud Firmware Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114. | 9.8 |
2020-07-17 | CVE-2020-15816 | Exposure of Resource to Wrong Sphere vulnerability in Westerndigital WD Discovery In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables. | 8.8 |
2020-05-13 | CVE-2020-12427 | Cross-Site Request Forgery (CSRF) vulnerability in Westerndigital WD Discovery 2.12.127 The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space. | 8.8 |
2020-04-15 | CVE-2020-10951 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Westerndigital IBI and MY Cloud Home Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages. | 4.7 |
2020-03-10 | CVE-2019-10705 | Insufficiently Protected Credentials vulnerability in Westerndigital products Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials. | 7.5 |
2020-03-10 | CVE-2019-11686 | Insufficiently Protected Credentials vulnerability in Westerndigital products Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure. | 5.5 |
2020-03-10 | CVE-2019-10706 | Insufficiently Protected Credentials vulnerability in Westerndigital products Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. | 6.3 |
2020-02-20 | CVE-2020-8960 | Cross-site Scripting vulnerability in Westerndigital Mycloud.Com Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS. | 6.1 |
2020-02-19 | CVE-2020-8959 | Uncontrolled Search Path Element vulnerability in Westerndigital products Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. | 7.8 |
2019-09-30 | CVE-2019-13467 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. | 5.9 |