Known Vulnerabilities for My Cloud Ex4100 by Westerndigital
Listed below are 10 of the newest known vulnerabilities associated with "My Cloud Ex4100" by "Westerndigital".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-23000 | The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forw... | 7.8 - HIGH | 2022-07-25 | 2022-08-03 |
| CVE-2022-22999 | Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with ... | 4.8 - MEDIUM | 2022-07-25 | 2022-08-01 |
| CVE-2022-22995 | The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By... | 9.8 - CRITICAL | 2022-03-25 | 2024-01-04 |
| CVE-2022-22994 | A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS ... | 9.8 - CRITICAL | 2022-01-28 | 2022-03-15 |
| CVE-2022-22993 | A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a... | 8.8 - HIGH | 2022-01-28 | 2022-03-18 |
| CVE-2022-22992 | A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow a... | 9.8 - CRITICAL | 2022-01-28 | 2023-07-11 |
| CVE-2022-22991 | A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loa... | 8.8 - HIGH | 2022-01-13 | 2022-01-21 |
| CVE-2022-22990 | A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution an... | 8.8 - HIGH | 2022-01-13 | 2023-07-11 |
| CVE-2022-22989 | My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited b... | 9.8 - CRITICAL | 2022-01-13 | 2023-10-12 |
| CVE-2021-3310 | Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead ... | 7.8 - HIGH | 2021-03-10 | 2021-03-17 |