CVE-2020-28940

On Western Digital My Cloud OS 5 devices before 5.06.115, the NAS Admin dashboard has an authentication bypass vulnerability that could allow an unauthenticated user to execute privileged commands on the device.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:westerndigital:my_cloud_os_5:*:*:*:*:*:*:*:*
OR cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*

Information

Published : 2020-12-01 08:15

Updated : 2022-04-26 09:35


NVD link : CVE-2020-28940

Mitre link : CVE-2020-28940


JSON object : View

CWE
CWE-287

Improper Authentication

Advertisement

dedicated server usa

Products Affected

westerndigital

  • my_cloud_os_5
  • my_cloud_pr2100
  • my_cloud_ex4100
  • my_cloud_mirror_gen_2
  • my_cloud_pr4100
  • my_cloud_ex2_ultra