VendorsWestern Digitalmy_cloud_os_5any version
Vulnerabilities

Western Digital My Cloud OS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2020-28940
On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.
Published 2020-12-01 · Modified
9.8EPSS 0.039
CVE-2020-28970
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie. (In addition, an upload endpoint could then be used by an authenticated administrator to upload executable PHP scripts.)
Published 2020-12-01 · Modified
9.8EPSS 0.039
CVE-2020-28971
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.
Published 2020-12-01 · Modified
9.8EPSS 0.038
CVE-2020-29563
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
Published 2020-12-11 · Modified
9.8EPSS 0.029
CVE-2022-36327
Path traversal vulnerability leading to an arbitrary file write in Western Digital devices
Published 2023-05-18 · Modified
9.8EPSS 0.015
CVE-2022-36328
Path Traversal Vulnerability leading to an arbitrary file read in Western Digital devices
Published 2023-05-18 · Modified
5.8EPSS 0.008
CVE-2022-36326
Resource Exhaustion Vulnerability in Western Digital devices
Published 2023-05-18 · Modified
4.9EPSS 0.006
CVE-2023-22813
Device API endpoint missing access controls on Western Digital Mobile and Web Apps
Published 2023-05-08 · Modified
4.3EPSS 0.005