Western Digital

First CVE: Jan 13, 2022Active for: 5 years
49
CVEs Published
More CVEs Published than 57% of tracked CNAs
9.8
Avg CVEs / Year
More Avg CVEs / Year than 53% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 68% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Western Digital as a CNA, 0.0% affect products that Western Digital develops as a vendor.

100.0%
Self-reported: 0Third-party: 49

Of all the CVEs published that affect products developed by Western Digital, 0.0% are self-published by Western Digital as a CNA.

100.0%
Self-published: 0Published by other CNAs: 8

Trends Over Time

The number and severity of CVEs published by Western Digital over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 13, 2022
4 years ago
Most Recent CVE
Jan 26, 2026
180 days ago

Top CVEs

All CVEs published by Western Digital as a CNA, regardless of affected vendor or product.

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This c
Jan 26, 20239.851NONO
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS platforms allows remote attackers to execute arbitrary system
Sep 29, 20259.334NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesyst
May 18, 20239.831NONO
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a
May 10, 20239.831NONO
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacke
Mar 25, 20229.831NONO
A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the
Jan 28, 20229.831NONO
DLL hijacking in the WD Discovery Installer in Western Digital WD Discovery 5.2.730 on Windows allows a local attacker to execute arbitrary code via placement of a crafted dll in t
Jan 26, 20268.930NONO
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and
May 10, 20239.830NONO
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. Thi
Jan 28, 20229.830NONO
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects My
Sep 27, 20249.229NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA49 CVEs
Severity distribution among all CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local10 (20.4%)
Network35 (71.4%)
Unknown0 (0.0%)
Physical1 (2.0%)
Adjacent Network3 (6.1%)
Attack Complexity
Low43 (87.8%)
High6 (12.2%)
Unknown0 (0.0%)
User Interaction
None40 (81.6%)
Unknown0 (0.0%)
Required6 (12.2%)
Privileges Required
Low9 (18.4%)
High6 (12.2%)
None34 (69.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Western Digital as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Western Digital as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs