Westerndigital

My Cloud Home Duo Firmware

13 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Published 05.02.2024 22:15:55
  • Last modified 21.11.2024 07:45:28

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital ...

  • EPSS 0.09%
  • Published 05.02.2024 22:15:54
  • Last modified 21.11.2024 07:45:28

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on...

  • EPSS 0.28%
  • Published 12.06.2023 18:15:09
  • Last modified 21.11.2024 07:12:48

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before ...

  • EPSS 0.11%
  • Published 18.05.2023 18:15:09
  • Last modified 21.11.2024 07:12:47

An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital ...

  • EPSS 0.27%
  • Published 18.05.2023 18:15:09
  • Last modified 21.11.2024 07:12:48

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Di...

  • EPSS 0.07%
  • Published 18.05.2023 18:15:09
  • Last modified 21.11.2024 07:12:48

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations w...

  • EPSS 0.09%
  • Published 10.05.2023 20:15:09
  • Last modified 21.11.2024 07:12:48

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My...

  • EPSS 0.21%
  • Published 10.05.2023 00:15:09
  • Last modified 21.11.2024 07:12:48

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitat...

  • EPSS 0.11%
  • Published 01.12.2022 17:15:11
  • Last modified 21.11.2024 06:59:47

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to ...

  • EPSS 0.15%
  • Published 09.11.2022 21:15:14
  • Last modified 21.11.2024 06:59:47

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow an attacker to abuse certain par...