PT-2020-14645 · Western Digital · Wd Discovery

Yoko Kho

·

Published

2020-07-17

·

Updated

2021-07-21

·

CVE-2020-15816

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Western Digital WD Discovery versions prior to 4.0.251.0
Description A malicious application running with standard user permissions could potentially execute code in the WD Discovery application's process through library injection by using DYLD environment variables.
Recommendations For versions prior to 4.0.251.0, update to version 4.0.251.0 or later to resolve the issue.

Fix

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15816

Affected Products

Wd Discovery