WDC Tracking Number: WDC-20010
Published: December 9, 2020
Last Updated: December 9, 2020
My Cloud OS 5 was vulnerable to a NAS Admin authentication bypass vulnerability. My Cloud Firmware 5.07.118 contains updates to help resolve this vulnerability and improve the security of your My Cloud devices.
For more information on the latest security updates, see the release notes: https://os5releasenotes.mycloud.com/#/
Addressed a NAS Admin authentication bypass vulnerability that could allow an unauthenticated user to gain access to the device. The vulnerability was addressed by enforcing tighter whitelisting rules.
CVE Number: CVE-2020-29563
Reported by: DEVCORE working with Trend Micro’s Zero Day Initiative
Masked the password of the remote backup process when viewing running processes with the admin user.