← Back

CVE-2020-27159

nvd nist
Published: Oct 27, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114

Affected (1)

My Cloud Firmware
Configuration A
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Before 5.04.114
Running on/withPlatform Versions
Westerndigital
My Cloud Ex4100
All versions
Westerndigital
My Cloud Expert Series Ex2
All versions
Westerndigital
My Cloud Mirror Gen 2
All versions
Westerndigital
My Cloud Pr2100
All versions
Westerndigital
My Cloud Pr4100
All versions

Timeline

No history available yet.