Show filters
26 Total Results
Displaying 21-26 of 26
Sort by:
Attacker Value
Unknown

CVE-2022-22989

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.
Attacker Value
Unknown

CVE-2021-3310

Disclosure Date: March 10, 2021 (last updated February 22, 2025)
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
Attacker Value
Unknown

CVE-2020-29563

Disclosure Date: December 12, 2020 (last updated February 22, 2025)
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
Attacker Value
Unknown

CVE-2020-28970

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)
Attacker Value
Unknown

CVE-2020-28971

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.
Attacker Value
Unknown

CVE-2020-28940

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.