CVE-2023-22813: Device API endpoint missing access controls on Western Digital Mobile and Web Apps
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy and missing authentication requirement for private IPs, a remote attacker on the same network as the device could obtain device information by convincing a victim user to visit an attacker-controlled server and issue a cross-site request.
This issue affects My Cloud OS 5 Mobile App: before 4.21.0; My Cloud Home Mobile App: before 4.21.0; ibi Mobile App: before 4.21.0; My Cloud OS 5 Web App: before 4.26.0-6126; My Cloud Home Web App: before 4.26.0-6126; ibi Web App: before 4.26.0-6126.
Other sources
A device API endpoint was missing access controls on Western Digital My Cloud OS 5 Mobile App on Android, iOS, Western Digital My Cloud Home Mobile App on iOS, Android, SanDIsk ibi Mobile App on Android, iOS, Western Digital WD Cloud Mobile App on Android, iOS, Western Digital My Cloud OS 5 Web App, Western Digital My Cloud Home Web App, SanDisk ibi Web App and the Western Digital WD Web App. Due to a permissive CORS policy and missing authentication requirement for private IPs, a remote attacker on the same network as the device could obtain device information by convincing a victim user to visit an attacker-controlled server and issue a cross-site request.This issue affects My Cloud OS 5 Mobile App: through 4.21.0; My Cloud Home Mobile App: through 4.21.0; ibi Mobile App: through 4.21.0; WD Cloud Mobile App: through 4.21.0; My Cloud OS 5 Web App: through 4.26.0-6126; My Cloud Home Web App: through 4.26.0-6126; ibi Web App: through 4.26.0-6126; WD Web App: through 4.26.0-6126.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-22813?
CVE-2023-22813 is a vulnerability found in Western Digital My Cloud OS 5 Mobile App, My Cloud Home Mobile App, SanDisk ibi Mobile App, and WD Cloud Mobile App.
How severe is CVE-2023-22813?
CVE-2023-22813 has a severity rating of medium (4.3).
Which devices are affected by CVE-2023-22813?
CVE-2023-22813 affects Western Digital My Cloud OS 5 Mobile App on Android and iOS, My Cloud Home Mobile App on iOS and Android, SanDisk ibi Mobile App on Android and iOS, and WD Cloud Mobile App on Android and iOS.
What is the vulnerability in CVE-2023-22813?
The vulnerability in CVE-2023-22813 is a missing access control issue in the device API endpoint.
Is there a fix available for CVE-2023-22813?
Yes, a fix/update is available. Please refer to the following link for more information: [link](https://www.westerndigital.com/support/product-security/wdc-23004-western-digital-my-cloud-os-5-my-cloud-home-sandisk-ibi-and-wd-cloud-mobile-and-web-app-update)