First published: Thu Sep 11 2014(Updated: )
The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Western Digital My Cloud | =4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5876 has a medium severity rating due to its potential for man-in-the-middle attacks.
To fix CVE-2014-5876, update the WD My Cloud application to a version that properly verifies X.509 certificates.
CVE-2014-5876 exploits the lack of verification of X.509 certificates in the WD My Cloud Android application.
Users of the WD My Cloud application version 4.0.0 on Android devices are affected by CVE-2014-5876.
Attackers can spoof servers and obtain sensitive information from users by leveraging CVE-2014-5876.