Vulnerabilities > Westerndigital

DATE CVE VULNERABILITY TITLE RISK
2020-10-27 CVE-2020-12830 Out-of-bounds Write vulnerability in Westerndigital MY Cloud Firmware
Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.
network
low complexity
westerndigital CWE-787
critical
9.8
2020-07-17 CVE-2020-15816 Exposure of Resource to Wrong Sphere vulnerability in Westerndigital WD Discovery
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
network
low complexity
westerndigital CWE-668
8.8
2020-05-13 CVE-2020-12427 Cross-Site Request Forgery (CSRF) vulnerability in Westerndigital WD Discovery 2.12.127
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
network
low complexity
westerndigital CWE-352
8.8
2020-04-15 CVE-2020-10951 Improper Restriction of Rendered UI Layers or Frames vulnerability in Westerndigital IBI and MY Cloud Home
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
network
low complexity
westerndigital CWE-1021
4.7
2020-03-10 CVE-2019-10705 Insufficiently Protected Credentials vulnerability in Westerndigital products
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.
network
low complexity
westerndigital CWE-522
7.5
2020-03-10 CVE-2019-11686 Insufficiently Protected Credentials vulnerability in Westerndigital products
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.
local
low complexity
westerndigital CWE-522
5.5
2020-03-10 CVE-2019-10706 Insufficiently Protected Credentials vulnerability in Westerndigital products
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest.
local
high complexity
westerndigital CWE-522
6.3
2020-02-20 CVE-2020-8960 Cross-site Scripting vulnerability in Westerndigital Mycloud.Com
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
network
low complexity
westerndigital CWE-79
6.1
2020-02-19 CVE-2020-8959 Uncontrolled Search Path Element vulnerability in Westerndigital products
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
local
low complexity
westerndigital CWE-427
7.8
2019-09-30 CVE-2019-13467 Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service.
network
high complexity
sandisk westerndigital
5.9