CVE-2023-22813MEDIUMCVSS 4.3fixed in 4.21.02023-05-08
CVE-2023-22813 [MEDIUM] CWE-200 CVE-2023-22813:
A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and
A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy
and missing authentication requirement for private
nvd