Westerndigital My Cloud Glacier Firmware vulnerabilities
2 known vulnerabilities affecting westerndigital/my_cloud_glacier_firmware.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-22817MEDIUMCVSS 5.5fixed in 5.27.1612024-02-05
CVE-2023-22817 [MEDIUM] CWE-918 CVE-2023-22817: Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local networ
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that refer to loopback. This issue affe
nvd
CVE-2023-22819MEDIUMCVSS 4.9fixed in 5.27.1612024-02-05
CVE-2023-22819 [MEDIUM] CWE-770 CVE-2023-22819: An uncontrolled resource consumption vulnerability issue that could arise by sending crafted request
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue r
nvd