CVE Vulnerabilities

CVE-2021-36226

Improper Verification of Cryptographic Signature

Published: Feb 06, 2023 | Modified: Feb 14, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Western Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
My_cloud_os Westerndigital * 5.02.104 (excluding)

References