CVE-2020-12830
9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Addressed multiple stack buffer overflow vulnerabilities that could allow an attacker to carry out escalation of privileges through unauthorized remote code execution in Western Digital My Cloud devices before 5.04.114.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.33% — more likely to be exploited than 88% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-10-27 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| westerndigital | my cloud ex4100 |
| westerndigital | my cloud expert series ex2 |
| westerndigital | my cloud firmware |
| westerndigital | my cloud mirror - gen 2 |
| westerndigital | my cloud pr2100 |
| westerndigital | my cloud pr4100 |
References
- https://support.wdc.com/downloads.aspx?g=907&lang=en
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
- https://support.wdc.com/downloads.aspx?g=907&lang=en
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
→ the Explorer · watch your stack · NVD