Описание
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-27159
- https://www.comparitech.com/blog/information-security/security-vulnerabilities-80000-devices-update-now
- https://www.westerndigital.com/support/productsecurity
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
Связанные уязвимости
CVSS3: 9.8
nvd
больше 5 лет назад
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
CVSS3: 9.8
fstec
больше 5 лет назад
Уязвимость компонента DsdkProxy.php микропрограммного обеспечения сетевого хранилища Western Digital MyCloud NAS, позволяющая нарушителю выполнить произвольный код