CVE-2020-29563
Western Digital MyCloud PR4100 nasAdmin Incorrect Authorization Authentication Bypass Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.07.118. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to gain access to the device.
Se detectó un problema en dispositivos Western Digital My Cloud OS versión 5 anteriores a 5.07.118. Una vulnerabilidad de omisión de autenticación de administrador del NAS podría permitir a un usuario no autenticado conseguir acceso al dispositivo
This vulnerability allows remote attackers to bypass authentication on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the mod_rewrite module. The issue results from the way the software parses URLs to make authorization decisions. An attacker can leverage this vulnerability to bypass authentication on the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-04 CVE Reserved
- 2020-12-11 CVE Published
- 2023-08-27 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-20-1446 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.westerndigital.com/support/productsecurity/wdc-20010-my-cloud-os5-firmware-5-07-118 | 2022-08-06 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 5.07.118 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 5.07.118" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex2 Ultra Search vendor "Westerndigital" for product "My Cloud Ex2 Ultra" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 5.07.118 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 5.07.118" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex4100 Search vendor "Westerndigital" for product "My Cloud Ex4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 5.07.118 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 5.07.118" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Mirror Gen 2 Search vendor "Westerndigital" for product "My Cloud Mirror Gen 2" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 5.07.118 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 5.07.118" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Pr2100 Search vendor "Westerndigital" for product "My Cloud Pr2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 5.07.118 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 5.07.118" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Pr4100 Search vendor "Westerndigital" for product "My Cloud Pr4100" | - | - |
Safe
|