// For flags

CVE-2021-35941

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.

Western Digital WD My Book Live (versiones 2.x y posteriores) y WD My Book Live Duo (todas las versiones) presentan una API de administrador que puede llevar a cabo una restauración de fábrica del sistema sin autenticación, tal como fue explotado en the wild en junio de 2021, una vulnerabilidad diferente a la CVE-2018-18472

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-29 CVE Reserved
  • 2021-06-29 CVE Published
  • 2024-03-14 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-306: Missing Authentication for Critical Function
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Westerndigital
Search vendor "Westerndigital"
Wd My Book Live Firmware
Search vendor "Westerndigital" for product "Wd My Book Live Firmware"
>= 2.0
Search vendor "Westerndigital" for product "Wd My Book Live Firmware" and version " >= 2.0"
-
Affected
in Westerndigital
Search vendor "Westerndigital"
Wd My Book Live
Search vendor "Westerndigital" for product "Wd My Book Live"
--
Safe
Westerndigital
Search vendor "Westerndigital"
Wd My Book Live Duo Firmware
Search vendor "Westerndigital" for product "Wd My Book Live Duo Firmware"
*-
Affected
in Westerndigital
Search vendor "Westerndigital"
Wd My Book Live Duo
Search vendor "Westerndigital" for product "Wd My Book Live Duo"
--
Safe