Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).

Project Subscriptions

Vendors Products
Westerndigital Subscribe
My Cloud Dl2100 Subscribe
My Cloud Dl4100 Subscribe
My Cloud Ex2100 Subscribe
My Cloud Ex2 Ultra Subscribe
My Cloud Ex4100 Subscribe
My Cloud Mirror Gen 2 Subscribe
My Cloud Os Subscribe
My Cloud Pr2100 Subscribe
My Cloud Pr4100 Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-26644 Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can lead to code execution and information disclosure (by reading local files).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T16:53:17.409Z

Reserved: 2021-01-26T00:00:00

Link: CVE-2021-3310

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-10T05:15:13.517

Modified: 2024-11-21T06:21:15.400

Link: CVE-2021-3310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses