Westerndigital My Cloud vulnerabilities
2 known vulnerabilities affecting westerndigital/my_cloud.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-22813MEDIUMCVSS 4.3fixed in 4.26.0-61262023-05-08
CVE-2023-22813 [MEDIUM] CWE-200 CVE-2023-22813:
A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and
A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy
and missing authentication requirement for private
nvd
CVE-2018-7928MEDIUMCVSS 4.6fixed in 8.1.2.3032018-10-09
CVE-2018-7928 [MEDIUM] CVE-2018-7928: There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the M
There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old account with a new one through special steps by exploit this vulnerability. As a re
nvd