CVE-2020-12427

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
13/05/2020
Last modified:
08/09/2021

Description

The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:westerndigital:wd_discovery:*:*:*:*:*:my_cloud_home:*:* 3.8.229 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*