CVE-2023-22814
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/07/2023
Last modified:
10/07/2023
Description
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack.<br />
<br />
<br />
This issue affects My Cloud OS 5 devices: before 5.26.202.<br />
<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:westerndigital:my_cloud_os:*:*:*:*:*:*:*:* | 5.02.104 (including) | 5.26.202 (excluding) |
| cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_mirror_g2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:westerndigital:wd_cloud:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



