The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
References
Link | Resource |
---|---|
https://support.wdc.com/downloads.aspx?g=907&lang=en | Vendor Advisory |
https://www.westerndigital.com/support/productsecurity/wdc-20004-wd-discovery-cross-site-request-forgery-csrf | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
No history.
Information
Published : 2020-05-13 15:15
Updated : 2021-09-08 17:22
NVD link : CVE-2020-12427
Mitre link : CVE-2020-12427
CVE.ORG link : CVE-2020-12427
JSON object : View
Products Affected
westerndigital
- wd_discovery
microsoft
- windows
apple
- macos
CWE
CWE-352
Cross-Site Request Forgery (CSRF)