CVE-2023-22813
Device API endpoint missing access controls on Western Digital Mobile and Web Apps
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy
and missing authentication requirement for private IPs, a remote attacker on
the same network as the device could obtain device information by convincing a
victim user to visit an attacker-controlled server and issue a cross-site
request.
This issue affects
My Cloud OS 5 Mobile App: before 4.21.0; My Cloud Home Mobile App: before 4.21.0; ibi Mobile App: before 4.21.0; My
Cloud OS 5 Web App: before 4.26.0-6126; My Cloud Home Web App: before 4.26.0-6126;
ibi Web App: before 4.26.0-6126.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-06 CVE Reserved
- 2023-05-08 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-862: Missing Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Westerndigital Search vendor "Westerndigital" | My Cloud Search vendor "Westerndigital" for product "My Cloud" | < 4.26.0-6126 Search vendor "Westerndigital" for product "My Cloud" and version " < 4.26.0-6126" | - |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | My Cloud Home Search vendor "Westerndigital" for product "My Cloud Home" | < 4.21.0 Search vendor "Westerndigital" for product "My Cloud Home" and version " < 4.21.0" | android |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | My Cloud Home Search vendor "Westerndigital" for product "My Cloud Home" | < 4.21.0 Search vendor "Westerndigital" for product "My Cloud Home" and version " < 4.21.0" | iphone_os |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | My Cloud Home Search vendor "Westerndigital" for product "My Cloud Home" | < 4.26.0-6126 Search vendor "Westerndigital" for product "My Cloud Home" and version " < 4.26.0-6126" | - |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 4.21.0 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 4.21.0" | android |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | My Cloud Os 5 Search vendor "Westerndigital" for product "My Cloud Os 5" | < 4.21.0 Search vendor "Westerndigital" for product "My Cloud Os 5" and version " < 4.21.0" | iphone_os |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | Sandisk Ibi Search vendor "Westerndigital" for product "Sandisk Ibi" | < 4.21.0 Search vendor "Westerndigital" for product "Sandisk Ibi" and version " < 4.21.0" | android |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | Sandisk Ibi Search vendor "Westerndigital" for product "Sandisk Ibi" | < 4.21.0 Search vendor "Westerndigital" for product "Sandisk Ibi" and version " < 4.21.0" | iphone_os |
Affected
| ||||||
Westerndigital Search vendor "Westerndigital" | Sandisk Ibi Search vendor "Westerndigital" for product "Sandisk Ibi" | < 4.26.0-6126 Search vendor "Westerndigital" for product "Sandisk Ibi" and version " < 4.26.0-6126" | - |
Affected
|