CVE-2020-27159

Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:westerndigital:my_cloud_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_expert_series_ex2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_mirror_-_gen_2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*

Information

Published : 2020-10-27 13:15

Updated : 2021-12-02 11:26


NVD link : CVE-2020-27159

Mitre link : CVE-2020-27159


JSON object : View

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Advertisement

dedicated server usa

Products Affected

westerndigital

  • my_cloud_pr2100
  • my_cloud_pr4100
  • my_cloud_mirror_-_gen_2
  • my_cloud_ex4100
  • my_cloud_expert_series_ex2
  • my_cloud_firmware