VendorsWestern Digitalmy_cloud_mirror_gen_2all versions
Vulnerabilities

Western Digital My Cloud Mirror Gen 2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2022-22995
Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in Netatalk
Published 2022-03-25 · Modified
10.0EPSS 0.027
CVE-2022-22992
Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.
Published 2022-01-28 · Modified
10.0EPSS 0.023
CVE-2020-28940
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.
Published 2020-12-01 · Modified
9.8EPSS 0.039
CVE-2020-28970
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)
Published 2020-12-01 · Modified
9.8EPSS 0.039
CVE-2020-28971
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.
Published 2020-12-01 · Modified
9.8EPSS 0.038
CVE-2020-29563
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
Published 2020-12-11 · Modified
9.8EPSS 0.029
CVE-2022-22994
Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability on Western Digital My Cloud devices.
Published 2022-01-28 · Modified
9.8EPSS 0.019
CVE-2022-22989
Pre-authenticated stack overflow vulnerability on FTP Service
Published 2022-01-13 · Modified
9.8EPSS 0.013
CVE-2022-22990
Limited authentication bypass vulnerability on Western Digital My Cloud devices
Published 2022-01-13 · Modified
8.8EPSS 0.021
CVE-2022-22991
Command injection through unsecured HTTP calls on Western Digital My Cloud devices
Published 2022-01-13 · Modified
8.8EPSS 0.013
CVE-2022-22993
Limited Server-Side Request Forgery vulnerability on Western Digital My Cloud devices.
Published 2022-01-28 · Modified
8.8EPSS 0.008
CVE-2021-3310
Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
Published 2021-03-10 · Modified
7.8EPSS 0.010