CVE-2021-36225: High severity western digital my cloud os 5 vulnerability
Published Feb 6, 2023
·Updated
Western Digital My Cloud devices before OS5 allow REST API access by low-privileged accounts, as demonstrated by API commands for firmware uploads and installation.
Affected Software
4 affected components
WesternDigital My Cloud Os<5.02.104
WesternDigital My Cloud Pr4100
All of the following
WesternDigital My Cloud Os<5.02.104
WesternDigital My Cloud Pr4100
Remediation
Patch Available
Event History
Feb 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-36225?
CVE-2021-36225 is a vulnerability found in Western Digital My Cloud devices before OS5, which allows REST API access by low-privileged accounts.
2
How severe is CVE-2021-36225?
CVE-2021-36225 has a severity rating of 8.8, which is considered high.
3
Which software versions are affected by CVE-2021-36225?
Western Digital My Cloud devices before OS5 with a version up to and excluding 5.02.104 are affected by CVE-2021-36225.
4
How can the vulnerability in CVE-2021-36225 be exploited?
The vulnerability in CVE-2021-36225 can be exploited through API commands for firmware uploads and installation.
5
Are Western Digital My Cloud PR4100 devices affected by CVE-2021-36225?
No, Western Digital My Cloud PR4100 devices are not affected by CVE-2021-36225.