Known Vulnerabilities for My Cloud Mirror Gen 2 by Westerndigital
Listed below are 10 of the newest known vulnerabilities associated with "My Cloud Mirror Gen 2" by "Westerndigital".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Westerndigital My Cloud Mirror Gen 2
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-34532 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6... | Not Provided | 2026-03-31 | 2026-03-31 |
| CVE-2022-22995 | The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By... | 9.8 - CRITICAL | 2022-03-25 | 2024-01-04 |
| CVE-2022-22994 | A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS ... | 9.8 - CRITICAL | 2022-01-28 | 2022-03-15 |
| CVE-2022-22993 | A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a... | 8.8 - HIGH | 2022-01-28 | 2022-03-18 |
| CVE-2022-22992 | A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow a... | 9.8 - CRITICAL | 2022-01-28 | 2023-07-11 |
| CVE-2022-22991 | A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loa... | 8.8 - HIGH | 2022-01-13 | 2022-01-21 |
| CVE-2022-22990 | A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution an... | 8.8 - HIGH | 2022-01-13 | 2023-07-11 |
| CVE-2022-22989 | My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited b... | 9.8 - CRITICAL | 2022-01-13 | 2023-10-12 |
| CVE-2021-3310 | Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead ... | 7.8 - HIGH | 2021-03-10 | 2021-03-17 |
| CVE-2020-28970 | An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerabi... | 9.8 - CRITICAL | 2020-12-01 | 2022-04-26 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Westerndigital | My Cloud Mirror Gen 2 | - | All | All | All |