Limited authentication bypass vulnerability on Western Digital My Cloud devices
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 2.1%
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Affected products
Western Digital · My Cloud