Authentication Bypass issue in My Cloud OS 5 devices

CVE Details

Basic Information

Title Authentication Bypass issue in My Cloud OS 5 devices
Type cve
Published 2023-06-30T23:05:43.130Z
Modified 2024-11-26T16:09:14.746Z

Product Information

Vendor Western Digital
Product My Cloud OS 5
Version 0

CVSS Information

Base Score 10.0 (CRITICAL)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

AI Analysis

AI Description An authentication bypass vulnerability in My Cloud OS 5 allows attackers to impersonate users by spoofing tokens, potentially leading to unauthorized access and malicious activities.
AI Severity Critical
AI Vendor Western Digital
AI Product My Cloud OS 5
AI Version before 5.26.202

Affected Products

  • Western Digital My Cloud OS 5 0

Additional Information

CWE List CWE-290
Source WDC PSIRT

Description

An authentication bypass issue via spoofing was discovered in the token-based authentication mechanism that could allow an attacker to carry out an impersonation attack.

This issue affects My Cloud OS 5 devices: before 5.26.202.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.