Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3w5-whrj-66qg

Опубликовано: 12 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.

EPSS

Процентиль: 51%
0.00283
Низкий

10 Critical

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 10
nvd
больше 2 лет назад

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.

CVSS3: 10
fstec
почти 3 года назад

Уязвимость операционных систем сетевых хранилищ My Cloud OS, связанная с с обходом аутентификации посредством спуфинга, позволяющая нарушителю получить доступ к пользовательским данным и выполнить произвольный код

EPSS

Процентиль: 51%
0.00283
Низкий

10 Critical

CVSS3

Дефекты

CWE-290