Skip to main content

Vendor/product archive

westerndigital / my_cloud CVEs

Beta · best-effort

25 CVEs tagged to westerndigital / my_cloud7 Critical, 8 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2023-22814

Published Jul 1, 2023

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This is…

CVSS 10.0 · Critical

CVE-2023-22816

Published Jun 30, 2023

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to build files with redirects and…

CVSS 6.0 · Medium

CVE-2023-22815

Published Jun 30, 2023

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in the context of the root user on…

CVSS 6.2 · Medium

CVE-2022-29840

Published May 10, 2023

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in West…

CVSS 5.1 · Medium

CVE-2022-29841

Published May 10, 2023

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location an…

CVSS 8.0 · High

CVE-2022-29842

Published May 10, 2023

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a…

CVSS 9.8 · Critical

CVE-2022-29839

Published Dec 9, 2022

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a re…

CVSS 4.1 · Medium

CVE-2022-29838

Published Dec 9, 2022

Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information i…

CVSS 4.3 · Medium

CVE-2022-22994

Published Jan 28, 2022

A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. Th…

CVSS 8.8 · High

CVE-2022-22993

Published Jan 28, 2022

A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing…

CVSS 7.8 · High

CVE-2022-22992

Published Jan 28, 2022

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the…

CVSS 7.8 · High

CVE-2022-22991

Published Jan 13, 2022

A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vu…

CVSS 7.8 · High

CVE-2022-22990

Published Jan 13, 2022

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Address…

CVSS 7.8 · High

CVE-2022-22989

Published Jan 13, 2022

My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed…

CVSS 9.8 · Critical

CVE-2018-7928

Published Oct 9, 2018

There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart ph…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1