7.8

CVE-2021-3310

Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Westerndigital ≫ My Cloud Os Version < 5.10.122
   Westerndigital ≫ My Cloud Dl2100 Version -
   Westerndigital ≫ My Cloud Dl4100 Version -
   Westerndigital ≫ My Cloud Ex2 Ultra Version -
   Westerndigital ≫ My Cloud Ex2100 Version -
   Westerndigital ≫ My Cloud Ex4100 Version -
   Westerndigital ≫ My Cloud Mirror Gen 2 Version -
   Westerndigital ≫ My Cloud Pr2100 Version -
   Westerndigital ≫ My Cloud Pr4100 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.01% 0.585
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://www.westerndigital.com/support/productsecurity/wdc-21002-my-cloud-firmware-version-5-10-122
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-277/
Third Party Advisory