CVE-2014-5876: Medium severity western digital my cloud vulnerability
The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5876?
CVE-2014-5876 has a medium severity rating due to its potential for man-in-the-middle attacks.
How do I fix CVE-2014-5876?
To fix CVE-2014-5876, update the WD My Cloud application to a version that properly verifies X.509 certificates.
What does CVE-2014-5876 exploit?
CVE-2014-5876 exploits the lack of verification of X.509 certificates in the WD My Cloud Android application.
Who is affected by CVE-2014-5876?
Users of the WD My Cloud application version 4.0.0 on Android devices are affected by CVE-2014-5876.
What can attackers achieve using CVE-2014-5876?
Attackers can spoof servers and obtain sensitive information from users by leveraging CVE-2014-5876.