Western Digital my cloud Vulnerabilities
CVE security advisories and vulnerability history for my cloud by Western Digital.
Last updated
Overview
Western Digital my cloud has 31 published CVE records since 2018, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 1 have a known public exploit. The average CVSS base score across scored CVEs is 8.3.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Western Digital my cloud, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list. Affected platforms include linux.
Severity and exploitation
How the CVSS severity of Western Digital my cloud's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Western Digital my cloud's CVEs are currently listed in CISA's KEV catalog.
Public exploits
1
One of Western Digital my cloud's CVEs has a known public exploit available.
Affected versions and CVEs
Browse every Western Digital my cloud version named in a CVE, then pick one to see only the CVEs that affect it.
Version ranges
- My Cloud OS 5 <= v < 5.19.1176 CVEs
- My Cloud <= v < 5.25.1242 CVEs
- My Cloud OS 5 <= v < 5.23.1142 CVEs
- My Cloud OS 5 <= v < 5.26.1192 CVEs
- < 4.26.0-61261 CVE
- < 5.29.1021 CVE
- < 5.31.1081 CVE
- < 8.1.2.3031 CVE
Fixed in
- 5.19.1176 CVEs
- 5.23.1142 CVEs
- 5.25.1242 CVEs
- 5.26.1192 CVEs
- 4.26.0-61261 CVE
- 5.29.1021 CVE
- 5.31.1081 CVE
- 8.1.2.3031 CVE
31 CVEs
- Critical · CVSS 9.3EPSS 1.1% (63th pct)2025-09-29
- Critical · CVSS 9.2EPSS 0.5% (38th pct)2024-09-27
- Critical · CVSS 10.0EPSS 0.7% (49th pct)2023-06-30
- Medium · CVSS 6.7EPSS 1.3% (68th pct)2023-06-30
- High · CVSS 8.8EPSS 0.9% (55th pct)2023-06-30
- Critical · CVSS 10.0EPSS 0.6% (45th pct)2023-06-12
- Medium · CVSS 5.8EPSS 0.8% (52th pct)2023-05-18
- Critical · CVSS 9.8EPSS 1.5% (71th pct)2023-05-18
- Medium · CVSS 4.9EPSS 0.6% (44th pct)2023-05-18
- Medium · CVSS 5.5EPSS 0.1% (4th pct)2023-05-10
- Critical · CVSS 9.8EPSS 1.5% (71th pct)2023-05-10
- Critical · CVSS 9.8EPSS 1.8% (77th pct)2023-05-10
- Medium · CVSS 4.3EPSS 0.5% (37th pct)2023-05-08
- Critical · CVSS 9.8EPSS 36.4% (98th pct)2023-01-25
- Critical · CVSS 9.8EPSS 1.2% (64th pct)2023-01-25
- Medium · CVSS 5.5EPSS 0.1% (4th pct)2022-12-09
- Medium · CVSS 4.6EPSS 0.3% (18th pct)2022-12-09
- High · CVSS 8.2EPSS 0.4% (28th pct)2022-07-25
- High · CVSS 7.8EPSS 0.2% (9th pct)2022-07-25
- Critical · CVSS 10.0EPSS 2.7% (84th pct)2022-03-25
- Critical · CVSS 9.8EPSS 1.9% (77th pct)2022-01-28
- Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.CVE-2022-22992PatchCritical · CVSS 9.8EPSS 2.3% (82th pct)2022-01-28
- High · CVSS 8.8EPSS 0.8% (51th pct)2022-01-28
- High · CVSS 8.8EPSS 2.1% (80th pct)2022-01-13
- High · CVSS 8.8EPSS 1.3% (68th pct)2022-01-13
- Critical · CVSS 9.8EPSS 1.3% (68th pct)2022-01-13
- High vulnerability · 2019-05-23CVE-2019-9949PatchHigh · CVSS 8.8EPSS 3.1% (86th pct)2019-05-23
- Critical vulnerability · 2019-04-24CVE-2019-9951PatchCritical · CVSS 9.8EPSS 1.7% (74th pct)2019-04-24
- Critical vulnerability · 2019-04-24CVE-2019-9950PatchCritical · CVSS 9.8EPSS 2.3% (82th pct)2019-04-24
- Medium vulnerability · 2018-10-09CVE-2018-7928PatchMedium · CVSS 4.6EPSS 0.3% (26th pct)2018-10-09
Showing 30 of 31
Common weakness types
The CWE weakness categories most often found in Western Digital my cloud CVEs. Follow any weakness for its full explanation.
- CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')6 CVEs
- CWE-287Improper Authentication2 CVEs
- CWE-290Authentication Bypass by Spoofing2 CVEs
- CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2 CVEs
- CWE-918Server-Side Request Forgery (SSRF)2 CVEs
- CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer1 CVE
- CWE-522Insufficiently Protected Credentials1 CVE
- CWE-59Improper Link Resolution Before File Access ('Link Following')1 CVE
Disclosure activity by year
How many Western Digital my cloud CVEs were published each year.
Other Western Digital products
Browse vulnerabilities for other products by Western Digital.
Frequently asked questions
Common questions about Western Digital my cloud vulnerabilities.
- How many CVEs does Western Digital my cloud have?
- Western Digital my cloud has 31 published CVE records since 2018.
- How many Western Digital my cloud CVEs are in CISA KEV?
- None of Western Digital my cloud's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Are there public exploits for Western Digital my cloud vulnerabilities?
- Yes — 1 of Western Digital my cloud's CVEs have a known public exploit.
- Which versions of Western Digital my cloud are affected?
- 16 distinct Western Digital my cloud versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
- What are the most common weakness types in Western Digital my cloud CVEs?
- Western Digital my cloud's CVEs most often map to these CWE weakness types: CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-287 (Improper Authentication), CWE-290 (Authentication Bypass by Spoofing), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- How many critical Western Digital my cloud vulnerabilities are there?
- Western Digital my cloud has 16 critical and 7 high-severity CVEs.
- What is the average severity of Western Digital my cloud CVEs?
- The average CVSS base score across Western Digital my cloud's scored CVEs is 8.3.
References
- All Western Digital vulnerabilities
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track Western Digital my cloud vulnerabilities
Monitor new Western Digital my cloud vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.