Lucene search

K
nvd[email protected]NVD:CVE-2021-36226
HistoryFeb 06, 2023 - 2:15 p.m.

CVE-2021-36226

2023-02-0614:15:08
CWE-347
web.nvd.nist.gov
2
western digital my cloud
firmware upgrade
cryptographically signed

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

72.8%

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

Affected configurations

Nvd
Node
westerndigitalmy_cloud_osRange<5.02.104
AND
westerndigitalmy_cloud_pr4100Match-
VendorProductVersionCPE
westerndigitalmy_cloud_os*cpe:2.3:o:westerndigital:my_cloud_os:*:*:*:*:*:*:*:*
westerndigitalmy_cloud_pr4100-cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.004

Percentile

72.8%

Related for NVD:CVE-2021-36226