PT-2020-4932 · Western Digital · Western Digital My Cloud

Published

2020-10-27

·

Updated

2021-12-02

·

CVE-2020-27159

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Western Digital My Cloud NAS devices prior to 5.04.114
Description: The issue exists due to insufficient validation of user input in the DsdkProxy.php component of Western Digital MyCloud NAS devices, allowing a remote attacker to execute arbitrary code.
Recommendations: For Western Digital My Cloud NAS devices prior to 5.04.114, update to version 5.04.114 or later to resolve the issue. As a temporary workaround, consider restricting access to the DsdkProxy.php component until a patch is applied.

Exploit

Fix

OS Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05507
CVE-2020-27159

Affected Products

Western Digital My Cloud