Vulnerability Name: | CVE-2021-33205 (CCN-203593) | ||||||||||||
Assigned: | 2021-06-10 | ||||||||||||
Published: | 2021-06-10 | ||||||||||||
Updated: | 2022-07-12 | ||||||||||||
Summary: | Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library and stealing user credentials. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-noinfo | ||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-33205 Source: XF Type: UNKNOWN westerndigital-cve202133205-priv-esc(203593) Source: CCN Type: Western Digital WDC-21007 EdgeRover Windows App Version 0.25 Source: CONFIRM Type: Vendor Advisory https://www.westerndigital.com/support/productsecurity/wdc-21007-edgerover-windows-app-ver-0-25 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |