CVE-2022-36326
- EPSS 0.11%
- Published 18.05.2023 18:15:09
- Last modified 21.11.2024 07:12:47
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital ...
CVE-2022-36327
- EPSS 0.27%
- Published 18.05.2023 18:15:09
- Last modified 21.11.2024 07:12:48
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Di...
CVE-2022-36328
- EPSS 0.07%
- Published 18.05.2023 18:15:09
- Last modified 21.11.2024 07:12:48
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations w...
CVE-2020-29563
- EPSS 5.62%
- Published 12.12.2020 00:15:12
- Last modified 21.11.2024 05:24:12
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
CVE-2020-28971
- EPSS 3.15%
- Published 01.12.2020 16:15:11
- Last modified 21.11.2024 05:23:24
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient v...
CVE-2020-28940
- EPSS 3.62%
- Published 01.12.2020 16:15:10
- Last modified 21.11.2024 05:23:20
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.
CVE-2020-28970
- EPSS 3.62%
- Published 01.12.2020 16:15:10
- Last modified 21.11.2024 05:23:24
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload e...