Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
2021-03-10T05:15:13.517
2024-11-21T06:21:15.400
Modified
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | westerndigital | my_cloud_os | < 5.10.122 | Yes |
Hardware | westerndigital | my_cloud_dl2100 | - | No |
Hardware | westerndigital | my_cloud_dl4100 | - | No |
Hardware | westerndigital | my_cloud_ex2_ultra | - | No |
Hardware | westerndigital | my_cloud_ex2100 | - | No |
Hardware | westerndigital | my_cloud_ex4100 | - | No |
Hardware | westerndigital | my_cloud_mirror_gen_2 | - | No |
Hardware | westerndigital | my_cloud_pr2100 | - | No |
Hardware | westerndigital | my_cloud_pr4100 | - | No |