Vulnerabilities
Vulnerable Software
Westerndigital:  Security Vulnerabilities
Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.
CVSS Score
9.8
EPSS Score
0.05
Published
2020-10-27
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
CVSS Score
9.8
EPSS Score
0.083
Published
2020-10-27
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
CVSS Score
8.8
EPSS Score
0.009
Published
2020-07-17
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
CVSS Score
8.8
EPSS Score
0.001
Published
2020-05-13
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
CVSS Score
4.7
EPSS Score
0.002
Published
2020-04-15
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-03-10
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
CVSS Score
6.3
EPSS Score
0.001
Published
2020-03-10
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.
CVSS Score
5.5
EPSS Score
0.001
Published
2020-03-10
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
CVSS Score
6.1
EPSS Score
0.005
Published
2020-02-20
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
CVSS Score
7.8
EPSS Score
0.001
Published
2020-02-19


Contact Us

Shodan ® - All rights reserved