Show filters
26 Total Results
Displaying 21-26 of 26
Sort by:
Attacker Value
Unknown
CVE-2022-22989
Disclosure Date: January 13, 2022 (last updated February 23, 2025)
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.
0
Attacker Value
Unknown
CVE-2021-3310
Disclosure Date: March 10, 2021 (last updated February 22, 2025)
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
0
Attacker Value
Unknown
CVE-2020-29563
Disclosure Date: December 12, 2020 (last updated February 22, 2025)
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
0
Attacker Value
Unknown
CVE-2020-28970
Disclosure Date: December 01, 2020 (last updated February 22, 2025)
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)
0
Attacker Value
Unknown
CVE-2020-28971
Disclosure Date: December 01, 2020 (last updated February 22, 2025)
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.
0
Attacker Value
Unknown
CVE-2020-28940
Disclosure Date: December 01, 2020 (last updated February 22, 2025)
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.
0