ZeroHour

CVE-2020-27159

PoC
CVSS 3.1
9.8 critical
EPSS
6%p93
Published
()
Modified
Description

Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114

Vendors
westerndigital
Products
my cloud firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.