CVE-2020-27744: OS Command Injection
Published Oct 29, 2020
·Updated
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.
Affected Software
6 affected components
WesternDigital My Cloud Firmware<5.04.114
WesternDigital My Cloud Ex2 Ultra
WesternDigital My Cloud Ex4100
WesternDigital My Cloud Mirror Gen2
WesternDigital My Cloud Pr2100
WesternDigital My Cloud Pr4100
Event History
Oct 29, 2020
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
Description
Frequently Asked Questions
1
What is CVE-2020-27744?
CVE-2020-27744 is a vulnerability found on Western Digital My Cloud NAS devices before version 5.04.114.
2
What is the severity of CVE-2020-27744?
The severity of CVE-2020-27744 is critical with a CVSS score of 9.8.
3
How does CVE-2020-27744 allow remote code execution?
CVE-2020-27744 allows remote code execution by exploiting a vulnerability on Western Digital My Cloud NAS devices.
4
Can CVE-2020-27744 lead to the escalation of privileges?
Yes, CVE-2020-27744 can result in the escalation of privileges.
5
How can I fix CVE-2020-27744?
To fix CVE-2020-27744, it is recommended to update to version 5.04.114 of the Western Digital My Cloud firmware.