Westerndigital

My Cloud Os

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 01.07.2023 00:15:09
  • Zuletzt bearbeitet 21.11.2024 07:45:28

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.

  • EPSS 0.53%
  • Veröffentlicht 30.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:45:28

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: befo...

  • EPSS 0.33%
  • Veröffentlicht 30.06.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 07:45:28

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over th...

  • EPSS 0.04%
  • Veröffentlicht 10.05.2023 23:15:09
  • Zuletzt bearbeitet 21.11.2024 06:59:47

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit ...

  • EPSS 0.25%
  • Veröffentlicht 10.05.2023 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:59:47

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This comma...

  • EPSS 0.87%
  • Veröffentlicht 10.05.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 06:59:47

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 de...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 06.02.2023 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:13:20

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 06.02.2023 14:15:08
  • Zuletzt bearbeitet 26.03.2025 19:15:15

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 06.02.2023 14:15:08
  • Zuletzt bearbeitet 26.03.2025 19:15:14

Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.

  • EPSS 0.05%
  • Veröffentlicht 09.12.2022 18:15:18
  • Zuletzt bearbeitet 21.11.2024 06:59:47

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This ...