Vulnerabilities > Westerndigital > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-30 CVE-2022-22996 Uncontrolled Search Path Element vulnerability in Westerndigital products
The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability.
local
low complexity
westerndigital CWE-427
7.8
2022-01-28 CVE-2022-22993 Server-Side Request Forgery (SSRF) vulnerability in Westerndigital MY Cloud OS
A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls.
low complexity
westerndigital CWE-918
8.8
2022-01-13 CVE-2022-22990 Incorrect Comparison vulnerability in Westerndigital MY Cloud OS
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices.
low complexity
westerndigital CWE-697
8.8
2022-01-13 CVE-2022-22991 Command Injection vulnerability in Westerndigital MY Cloud OS
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call.
low complexity
westerndigital CWE-77
8.8
2021-06-29 CVE-2021-35941 Missing Authentication for Critical Function vulnerability in Westerndigital products
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
network
low complexity
westerndigital CWE-306
7.5
2021-06-11 CVE-2021-33205 Unspecified vulnerability in Westerndigital Edgerover
Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used.
network
low complexity
westerndigital
8.8
2021-03-10 CVE-2021-3310 Link Following vulnerability in Westerndigital MY Cloud OS
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares.
local
low complexity
westerndigital CWE-59
7.8
2020-12-12 CVE-2020-29654 Uncontrolled Search Path Element vulnerability in Westerndigital Dashboard
Western Digital Dashboard before 3.2.2.9 allows DLL Hijacking that leads to compromise of the SYSTEM account.
local
low complexity
westerndigital CWE-427
7.8
2020-07-17 CVE-2020-15816 Exposure of Resource to Wrong Sphere vulnerability in Westerndigital WD Discovery
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
network
low complexity
westerndigital CWE-668
8.8
2020-05-13 CVE-2020-12427 Cross-Site Request Forgery (CSRF) vulnerability in Westerndigital WD Discovery 2.12.127
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
network
low complexity
westerndigital CWE-352
8.8