CVE-2020-27160: Path Traversal
Published Oct 27, 2020
·Updated
Addressed remote code execution vulnerability in AvailableApps.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114 (issue 3 of 3).
Affected Software
6 affected components
WesternDigital My Cloud Firmware<5.04.114
WesternDigital My Cloud Ex4100
WesternDigital My Cloud Expert Series Ex2
WesternDigital My Cloud Mirror - Gen 2
WesternDigital My Cloud Pr2100
WesternDigital My Cloud Pr4100
Event History
Oct 27, 2020
CVE Published
via MITRE·07:41 PM
Data Sourced
via MITRE·07:41 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-27160.
2
What is the severity level of CVE-2020-27160?
The severity level of CVE-2020-27160 is critical.
3
Which devices are affected by CVE-2020-27160?
The Western Digital My Cloud NAS devices prior to version 5.04.114 are affected by CVE-2020-27160.
4
How can I fix CVE-2020-27160?
To fix CVE-2020-27160, update your Western Digital My Cloud NAS device to version 5.04.114 or later.
5
Are my Western Digital My Cloud Expert Series Ex2 and My Cloud Mirror - Gen 2 devices vulnerable to CVE-2020-27160?
No, the Western Digital My Cloud Expert Series Ex2 and My Cloud Mirror - Gen 2 devices are not vulnerable to CVE-2020-27160.