CVE-2021-36224: Critical severity western digital my cloud os 5 vulnerability
Published Feb 6, 2023
·Updated
Western Digital My Cloud devices before OS5 have a nobody account with a blank password.
Affected Software
2 affected components
WesternDigital My Cloud Os<5.02.104
WesternDigital My Cloud Pr4100
Remediation
Patch Available
Event History
Feb 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2021-36224?
CVE-2021-36224 is a vulnerability found in Western Digital My Cloud devices prior to OS5 that allows unauthorized access through a blank password in the nobody account.
2
How severe is CVE-2021-36224?
CVE-2021-36224 has a severity rating of 9.8, which is classified as critical.
3
How can I fix CVE-2021-36224?
To fix CVE-2021-36224, users should update their Western Digital My Cloud devices to OS5 or apply the necessary patches provided by the vendor.
4
Are Western Digital My Cloud Pr4100 devices affected by CVE-2021-36224?
No, Western Digital My Cloud Pr4100 devices are not affected by CVE-2021-36224.
5
Is there any additional information available on CVE-2021-36224?
Yes, you can find more information on CVE-2021-36224 in the provided references: [link1], [link2], [link3].