CVE-2021-35941
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 12.71% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- westerndigital/wd my book live firmware · westerndigital/wd my book live duo firmware
- Source
- cve@mitre.org
References
- https://arstechnica.com/gadgets/2021/06/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices/Exploit, Third Party Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduoVendor Advisory
- https://arstechnica.com/gadgets/2021/06/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices/Exploit, Third Party Advisory
- https://www.westerndigital.com/support/productsecurity/wdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduoVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.