Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

Project Subscriptions

Vendors Products
Westerndigital Subscribe
Wd My Book Live Subscribe
Wd My Book Live Duo Subscribe
Wd My Book Live Duo Firmware Subscribe
Wd My Book Live Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-22576 Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T00:40:47.536Z

Reserved: 2021-06-29T00:00:00

Link: CVE-2021-35941

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-29T21:15:07.880

Modified: 2024-11-21T06:12:47.760

Link: CVE-2021-35941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses