Vulnerabilities > Westerndigital > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-17 CVE-2020-15816 Injection vulnerability in Westerndigital WD Discovery
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
network
low complexity
westerndigital CWE-74
6.5
2020-05-13 CVE-2020-12427 Cross-Site Request Forgery (CSRF) vulnerability in Westerndigital WD Discovery 2.12.127
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
6.8
2020-04-15 CVE-2020-10951 Improper Restriction of Rendered UI Layers or Frames vulnerability in Westerndigital IBI and MY Cloud Home
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
network
low complexity
westerndigital CWE-1021
4.7
2020-03-10 CVE-2019-10705 Insufficiently Protected Credentials vulnerability in Westerndigital products
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.
4.3
2020-03-10 CVE-2019-10706 Insufficiently Protected Credentials vulnerability in Westerndigital products
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest.
6.3
2020-02-20 CVE-2020-8960 Cross-site Scripting vulnerability in Westerndigital Mycloud.Com
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
4.3
2020-02-19 CVE-2020-8959 Uncontrolled Search Path Element vulnerability in Westerndigital products
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
4.4
2019-09-30 CVE-2019-13467 Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are potentially vulnerable to man-in-the-middle attacks when the applications download resources from the Dashboard web service. 4.3
2019-09-30 CVE-2019-13466 Use of Hard-coded Credentials vulnerability in multiple products
Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control.
network
low complexity
sandisk westerndigital CWE-798
5.0
2018-03-30 CVE-2018-9148 Improper Authentication vulnerability in Westerndigital MY Cloud Firmware 04.05.00320
Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory.
network
low complexity
westerndigital CWE-287
5.0