westerndigital Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with westerndigital products.
Products
- my_cloud_os_52 vulnerabilities
- my_cloud_dl2100_firmware1 vulnerability
- my_cloud_dl4100_firmware1 vulnerability
- my_cloud_ex2100_firmware1 vulnerability
- my_cloud_ex2_ultra_firmware1 vulnerability
- my_cloud_ex4100_firmware1 vulnerability
- my_cloud_firmware1 vulnerability
- my_cloud_mirror_g2_firmware1 vulnerability
- my_cloud_pr2100_firmware1 vulnerability
- my_cloud_pr4100_firmware1 vulnerability
- sandisk_privateaccess1 vulnerability
- wd_cloud_firmware1 vulnerability
- wd_discovery1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-22170CRITICAL | Unchecked buffer in Dynamic DNS clientImproper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My Cloud: before 5.29.102. CWE-119Sep 27, 2024 | CVSS9.2v4.0 | EPSS0.468% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22169HIGH | Misconfiguration in node.js causing a code execution in WD DiscoveryWD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with standard user permissions can exploit this vulnerability, enabling code execution within WD Discovery application's context. WD Discovery version 5.0.589 addresses this issue by disabling certain features and fuses in Electron. The attack vector for this issue re… CWE-94Aug 2, 2024 | CVSS7.1v4.0 | EPSS0.259% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-22167HIGH | SanDisk PrivateAccess DLL Hijacking VulnerabilityA potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system user. This vulnerability is only exploitable locally if an attacker has access to a copy of the user's vault or has already gained access into a user's system. This attack is limited to the system in context and cannot be propagated. CWE-427Mar 13, 2024 | CVSS7.9v3.1 | EPSS0.186% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22814CRITICAL | Authentication Bypass issue in My Cloud OS 5 devicesAn authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202. CWE-290Jun 30, 2023 | CVSS10.0v3.1 | EPSS0.687% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-22816MEDIUM | Limited Post-Authentication Remote Command Injection in My Cloud ProductsA post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and execute larger payloads. This issue affects My Cloud OS 5 devices: before 5.26.300. | CVSS6.0v3.1 | EPSS0.866% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |