Vulnerability index

Browse CVEs

69 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

My Cloud Pr2100 Firmware MEDIUM 5.5
CVE-2023-22817

Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to …

Fix: 5.27.161+
Fix from $1,600 2024-02-05
Sandisk Security Installer HIGH 7.8
CVE-2023-22818

Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local a…

Fix: 1.0.0.25+
Fix from $1,950 2023-11-15
My Cloud Os CRITICAL 9.8
CVE-2023-22814

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an i…

Fix: 5.26.202+
Fix from $2,300 2023-07-01
My Cloud Os HIGH 8.8
CVE-2023-22816

A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that could allow an attacker to b…

Fix: 5.26.300+
Fix from $1,950 2023-06-30
My Cloud Os MEDIUM 6.7
CVE-2023-22815

Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an attacker to execute code in t…

Fix: 5.26.300+
Fix from $1,600 2023-06-30
My Cloud Pr2100 Firmware HIGH 7.5
CVE-2022-36331

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an un…

Fix: 5.25.132+
Fix from $1,950 2023-06-12
My Cloud Os 5 CRITICAL 9.8
CVE-2022-36327

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations…

Fix: 5.26.202 / 9.4.0-191+
Fix from $2,300 2023-05-18
My Cloud Os MEDIUM 5.5
CVE-2022-29840

Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback…

Fix: 5.26.202+
Fix from $1,600 2023-05-10
My Cloud Os CRITICAL 9.8
CVE-2022-29841

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files…

Fix: 5.26.119+
Fix from $2,300 2023-05-10
My Cloud Os CRITICAL 9.8
CVE-2022-29842

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the…

Fix: 5.26.119+
Fix from $2,300 2023-05-10
My Cloud Home Firmware HIGH 7.5
CVE-2022-36329

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Dig…

Fix: 9.4.0-191+
Fix from $1,950 2023-05-10
My Cloud Home Duo Firmware HIGH 8.1
CVE-2022-36330

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western …

Fix: 9.4.0-191+
Fix from $1,950 2023-05-10
Sandisk Privateaccess HIGH 7.4
CVE-2023-22812

SanDisk PrivateAccess versions prior to 6.4.9 support insecure TLS 1.0 and TLS 1.1 protocols which are susceptible to man-in-the-middle attacks there…

Fix: 6.4.9+
Fix from $1,950 2023-03-24
My Cloud Os CRITICAL 9.8
CVE-2021-36224

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

Fix: 5.02.104+
Fix from $2,300 2023-02-06
My Cloud Os CRITICAL 9.8
CVE-2021-36226

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

Fix: 5.02.104+
Fix from $2,300 2023-02-06
My Cloud Os HIGH 8.8
CVE-2021-36225

Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads an…

Fix: 5.02.104+
Fix from $1,950 2023-02-06
My Cloud Pr2100 Firmware CRITICAL 9.8
CVE-2022-29843

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.…

Fix: 5.26.119+
Fix from $2,300 2023-01-26
My Cloud Pr2100 Firmware CRITICAL 9.8
CVE-2022-29844EPSS 36%

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read an…

Fix: 5.26.119+
Fix from $2,300 2023-01-26
My Cloud Os MEDIUM 5.5
CVE-2022-29839

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker…

Fix: 5.25.124+
Fix from $1,600 2022-12-09
My Cloud Home Firmware HIGH 7.8
CVE-2022-29837

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to ini…

Fix: 8.12.0-178+
Fix from $1,950 2022-12-01
My Cloud Home Firmware MEDIUM 6.7
CVE-2022-23006

A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attack…

Fix: 8.10.0-117+
Fix from $1,600 2022-09-27
Wd Discovery MEDIUM 5.3
CVE-2022-29835

WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certi…

Fix: 4.4.396+
Fix from $1,600 2022-09-19
Sweet B MEDIUM 5.3
CVE-2022-23001

When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user lev…

Mitigation only
Fix from $1,600 2022-07-29
Sweet B MEDIUM 5.3
CVE-2022-23002

When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting output is not properly reduced…

Mitigation only
Fix from $1,600 2022-07-29
Sweet B MEDIUM 5.3
CVE-2022-23003

When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not p…

Mitigation only
Fix from $1,600 2022-07-29
Sweet B MEDIUM 5.3
CVE-2022-23004

When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned …

Mitigation only
Fix from $1,600 2022-07-29
My Cloud Pr2100 Firmware HIGH 7.8
CVE-2022-23000

The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was e…

Fix: 5.23.114+
Fix from $1,950 2022-07-25
My Cloud Home Duo Firmware CRITICAL 9.8
CVE-2022-22997

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed …

Fix: 8.5.1-102+
Fix from $2,300 2022-07-12
My Cloud Home Duo Firmware HIGH 7.5
CVE-2022-22998

Implemented protections on AWS credentials that were not properly protected.

Fix: 8.5.1-102+
Fix from $1,950 2022-07-12
Sandisk Professional G Raid 4\/8 Software Utility HIGH 7.8
CVE-2022-22996

The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitation could lead to arbitrary co…

Fix: 6.2.0.16-2 / 300520006-2+
Fix from $1,950 2022-03-30