📦 My Cloud Os

by Westerndigital

🔍 What is My Cloud Os?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-22814

CRITICAL CVSS 10.0 Jul 1, 2023

This vulnerability allows attackers to bypass authentication by spoofing tokens, enabling impersonation attacks on affected My Cloud OS 5 devices. It impacts users of these devices running firmware ve...

CVE-2021-36224

CRITICAL CVSS 9.8 Feb 6, 2023

This vulnerability allows unauthenticated attackers to gain root access to Western Digital My Cloud network-attached storage devices by exploiting a default 'nobody' account with a blank password. It ...

CVE-2021-36226

CRITICAL CVSS 9.8 Feb 6, 2023

Western Digital My Cloud devices running firmware before OS5 lack cryptographic signature verification for firmware updates, allowing attackers to upload and execute malicious firmware. This affects a...

CVE-2022-22989

CRITICAL CVSS 9.8 Jan 13, 2022

CVE-2022-22989 is a critical pre-authentication stack overflow vulnerability in My Cloud OS 5's FTP service that allows unauthenticated attackers on the same network to execute arbitrary code. This af...

CVE-2022-22992

HIGH CVSS 7.8 Jan 28, 2022

This CVE describes a command injection vulnerability in Western Digital My Cloud devices that allows remote attackers to execute arbitrary system commands. The vulnerability occurs when user input is ...

CVE-2022-22994

HIGH CVSS 8.8 Jan 28, 2022

This CVE describes a remote code execution vulnerability in Western Digital My Cloud NAS devices where attackers can exploit insufficient verification of HTTP calls to trick the device into loading ma...

CVE-2022-22990

HIGH CVSS 7.8 Jan 13, 2022

CVE-2022-22990 is an authentication bypass vulnerability in Western Digital My Cloud devices that allows attackers to bypass limited authentication checks, potentially leading to remote code execution...

CVE-2021-3310

HIGH CVSS 7.8 Mar 10, 2021

Western Digital My Cloud OS 5 devices before version 5.10.122 have a symbolic link following vulnerability in SMB and AFP shares. This allows attackers to read local files (information disclosure) and...