Vulnerability Details CVE-2020-28971
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.031
EPSS Ranking 86.3%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Products affected by CVE-2020-28971
-
cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-
-
cpe:2.3:h:westerndigital:my_cloud_ex4100:-
-
cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-
-
cpe:2.3:h:westerndigital:my_cloud_pr2100:-
-
cpe:2.3:h:westerndigital:my_cloud_pr4100:-
-
cpe:2.3:o:westerndigital:my_cloud_os_5:5.02.104
-
cpe:2.3:o:westerndigital:my_cloud_os_5:5.03.103
-
cpe:2.3:o:westerndigital:my_cloud_os_5:5.04.114
-
cpe:2.3:o:westerndigital:my_cloud_os_5:5.05.111