Description
An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack.


This issue affects My Cloud OS 5 devices: before 5.26.202.

Published: 2023-06-30
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-26926 An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack. This issue affects My Cloud OS 5 devices: before 5.26.202.
History

Tue, 26 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Westerndigital my Cloud Os 5
CPEs cpe:2.3:a:westerndigital:my_cloud_os_5:*:*:*:*:*:iphone_os:*:*
Vendors & Products Westerndigital my Cloud Os 5
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Westerndigital My Cloud My Cloud Dl2100 My Cloud Dl4100 My Cloud Ex2100 My Cloud Ex2 Ultra My Cloud Ex4100 My Cloud Mirror G2 My Cloud Os My Cloud Os 5 My Cloud Pr2100 My Cloud Pr4100 Wd Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2024-11-26T16:09:14.746Z

Reserved: 2023-01-06T20:23:44.300Z

Link: CVE-2023-22814

cve-icon Vulnrichment

Updated: 2024-08-02T10:20:30.854Z

cve-icon NVD

Status : Modified

Published: 2023-07-01T00:15:09.970

Modified: 2024-11-21T07:45:28.200

Link: CVE-2023-22814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses