Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4hg9-r3gw-2m9q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

EPSS

Процентиль: 87%
0.03145
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-287

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.

EPSS

Процентиль: 87%
0.03145
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-287