CVE-2020-27744
9.8
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.16% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-10-29 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| westerndigital | my cloud ex2 ultra |
| westerndigital | my cloud ex4100 |
| westerndigital | my cloud firmware |
| westerndigital | my cloud mirror gen2 |
| westerndigital | my cloud pr2100 |
| westerndigital | my cloud pr4100 |
References
- https://www.comparitech.com/blog/information-security/security-vulnerabilities-80000-devices-update-now/
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
- https://www.comparitech.com/blog/information-security/security-vulnerabilities-80000-devices-update-now/
- https://www.westerndigital.com/support/productsecurity/wdc-20007-my-cloud-firmware-version-5-04-114
→ the Explorer · watch your stack · NVD