Westerndigital
Westerndigital MY Cloud OS 5: vulnerabilidades y CVE
Westerndigital MY Cloud OS 5 tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-36328 | Media (4.9) | 0.77% | — | 18 may 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords,… |
| CVE-2022-36327 | Crítica (9.8) | 1.5% | — | 18 may 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code… |
| CVE-2022-36326 | Media (4.9) | 0.57% | — | 18 may 2023 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was… |
| CVE-2023-22813 | Media (4.3) | 0.46% | — | 8 may 2023 | A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App,… |
| CVE-2020-29563 | Crítica (9.8) | 2.9% | — | 12 dic 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device. |
| CVE-2020-28971 | Crítica (9.8) | 3.8% | — | 1 dic 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a… |
| CVE-2020-28970 | Crítica (9.8) | 3.9% | — | 1 dic 2020 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a… |
| CVE-2020-28940 | Crítica (9.8) | 3.9% | — | 1 dic 2020 | On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device. |
Otros productos de Westerndigital
MY Cloud OS · 18MY Cloud Home Firmware · 14MY Cloud Home DUO Firmware · 13MY Cloud Firmware · 12MY Cloud Pr4100 Firmware · 11Sandisk IBI Firmware · 11MY Cloud Dl2100 Firmware · 10MY Cloud EX2 Ultra Firmware · 10MY Cloud Dl4100 Firmware · 10MY Cloud Ex4100 Firmware · 10MY Cloud Ex2100 Firmware · 10MY Cloud Pr2100 Firmware · 9