Vulnerabilities > Westerndigital > High

DATE CVE VULNERABILITY TITLE RISK
2022-01-28 CVE-2022-22994 Insufficient Verification of Data Authenticity vulnerability in Westerndigital MY Cloud OS
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call.
network
low complexity
westerndigital CWE-345
7.5
2022-01-13 CVE-2022-22990 Incorrect Comparison vulnerability in Westerndigital MY Cloud OS
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices.
low complexity
westerndigital CWE-697
8.8
2022-01-13 CVE-2022-22991 Command Injection vulnerability in Westerndigital MY Cloud OS
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call.
low complexity
westerndigital CWE-77
8.3
2020-12-12 CVE-2020-29563 Improper Authentication vulnerability in Westerndigital MY Cloud OS 5
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118.
network
low complexity
westerndigital CWE-287
7.5
2020-12-01 CVE-2020-28971 Improper Authentication vulnerability in Westerndigital MY Cloud OS 5
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115.
network
low complexity
westerndigital CWE-287
7.5
2020-12-01 CVE-2020-28970 Improper Authentication vulnerability in Westerndigital MY Cloud OS 5
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115.
network
low complexity
westerndigital CWE-287
7.5
2020-12-01 CVE-2020-28940 Improper Authentication vulnerability in Westerndigital MY Cloud OS 5
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.
network
low complexity
westerndigital CWE-287
7.5
2020-10-27 CVE-2020-27160 Path Traversal vulnerability in Westerndigital MY Cloud Firmware
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).
network
low complexity
westerndigital CWE-22
7.5
2020-10-27 CVE-2020-12830 Out-of-bounds Write vulnerability in Westerndigital MY Cloud Firmware 04.05.00320
Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.
network
low complexity
westerndigital CWE-787
7.5
2019-09-18 CVE-2019-16399 Use of Hard-coded Credentials vulnerability in Westerndigital WD MY Book Firmware
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to access the /admin/ directory without credentials.
network
low complexity
westerndigital CWE-798
7.5