CVE-2020-15816

HIGH

WD Discovery < 4.0.251.0 - Unauthenticated Remote Code Execution via DYLD Environment Variable Injection

Title source: llm
STIX 2.1

Description

In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.

Scores

CVSS v3 8.8
EPSS 0.0351
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-668
Status published
Products (1)
westerndigital/wd_discovery < 4.0.251.0 (2 CPE variants)
Published Jul 17, 2020
Tracked Since Feb 18, 2026