Skip to main content

Vendor archive

westerndigital CVEs

Beta · best-effort

83 CVEs tagged to vendor westerndigital23 Critical, 26 High, 30 Medium, 4 Low, 0 Unrated.

CVE-2023-22818

Published Nov 15, 2023

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary cod…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22814

Published Jul 1, 2023

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This is…

CVSS 10.0 · Critical

CVE-2023-22816

Published Jun 30, 2023

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and…

CVSS 6.0 · Medium

CVE-2023-22815

Published Jun 30, 2023

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on…

CVSS 6.2 · Medium

CVE-2022-29840

Published May 10, 2023

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in West…

CVSS 5.1 · Medium

CVE-2022-29841

Published May 10, 2023

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location an…

CVSS 8.0 · High

CVE-2022-29842

Published May 10, 2023

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a…

CVSS 9.8 · Critical

CVE-2023-22812

Published Mar 24, 2023

SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks thereby compromising confidentialit…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29839

Published Dec 9, 2022

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a re…

CVSS 4.1 · Medium

CVE-2022-29838

Published Dec 9, 2022

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information i…

CVSS 4.3 · Medium
Showing 1-25 of 83 CVEsPage 1 of 4