CVE-2021-35941

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
29/06/2021
Last modified:
12/07/2022

Description

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:westerndigital:wd_my_book_live_firmware:*:*:*:*:*:*:*:* 2.0 (including)
cpe:2.3:h:westerndigital:wd_my_book_live:-:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:wd_my_book_live_duo_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:wd_my_book_live_duo:-:*:*:*:*:*:*:*