The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
References
Link | Resource |
---|---|
https://support.wdc.com/downloads.aspx?g=907&lang=en | Vendor Advisory |
https://www.westerndigital.com/support/productsecurity/wdc-20004-wd-discovery-cross-site-request-forgery-csrf | Vendor Advisory |
https://support.wdc.com/downloads.aspx?g=907&lang=en | Vendor Advisory |
https://www.westerndigital.com/support/productsecurity/wdc-20004-wd-discovery-cross-site-request-forgery-csrf | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:59
Type | Values Removed | Values Added |
---|---|---|
References | () https://support.wdc.com/downloads.aspx?g=907&lang=en - Vendor Advisory | |
References | () https://www.westerndigital.com/support/productsecurity/wdc-20004-wd-discovery-cross-site-request-forgery-csrf - Vendor Advisory |
Information
Published : 2020-05-13 15:15
Updated : 2024-11-21 04:59
NVD link : CVE-2020-12427
Mitre link : CVE-2020-12427
CVE.ORG link : CVE-2020-12427
JSON object : View
Products Affected
apple
- macos
microsoft
- windows
westerndigital
- wd_discovery
CWE
CWE-352
Cross-Site Request Forgery (CSRF)