CVE-2023-22814
- EPSS 0.07%
- Veröffentlicht 01.07.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:45:28
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
CVE-2023-22816
- EPSS 0.53%
- Veröffentlicht 30.06.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:45:28
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: befo...
CVE-2023-22815
- EPSS 0.33%
- Veröffentlicht 30.06.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:45:28
Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on vulnerable CGI files. This vulnerability can only be exploited over th...
CVE-2022-29840
- EPSS 0.04%
- Veröffentlicht 10.05.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 06:59:47
Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit ...
CVE-2022-29841
- EPSS 0.25%
- Veröffentlicht 10.05.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 06:59:47
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This comma...
CVE-2022-29842
- EPSS 0.87%
- Veröffentlicht 10.05.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:47
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 de...
CVE-2021-36224
- EPSS 0.08%
- Veröffentlicht 06.02.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:20
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
CVE-2021-36226
- EPSS 0.04%
- Veröffentlicht 06.02.2023 14:15:08
- Zuletzt bearbeitet 26.03.2025 19:15:15
Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.
CVE-2021-36225
- EPSS 0.07%
- Veröffentlicht 06.02.2023 14:15:08
- Zuletzt bearbeitet 26.03.2025 19:15:14
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
CVE-2022-29839
- EPSS 0.05%
- Veröffentlicht 09.12.2022 18:15:18
- Zuletzt bearbeitet 21.11.2024 06:59:47
Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This ...