4.3

CVE-2023-22813










A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy
and missing authentication requirement for private IPs, a remote attacker on
the same network as the device could obtain device information by convincing a
victim user to visit an attacker-controlled server and issue a cross-site
request.



This issue affects
My Cloud OS 5 Mobile App: before 4.21.0; My Cloud Home Mobile App: before 4.21.0; ibi Mobile App: before 4.21.0; My
Cloud OS 5 Web App: before 4.26.0-6126; My Cloud Home Web App: before 4.26.0-6126;
ibi Web App: before 4.26.0-6126.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WesterndigitalMy Cloud SwPlatform- Version < 4.26.0-6126
WesterndigitalMy Cloud Home SwPlatformandroid Version < 4.21.0
WesterndigitalMy Cloud Home SwPlatformiphone_os Version < 4.21.0
WesterndigitalMy Cloud Home SwPlatform- Version < 4.26.0-6126
WesterndigitalMy Cloud Os 5 SwPlatformandroid Version < 4.21.0
WesterndigitalMy Cloud Os 5 SwPlatformiphone_os Version < 4.21.0
WesterndigitalSandisk Ibi SwPlatformandroid Version < 4.21.0
WesterndigitalSandisk Ibi SwPlatformiphone_os Version < 4.21.0
WesterndigitalSandisk Ibi SwPlatform- Version < 4.26.0-6126
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.305
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
psirt@wdc.com 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.