CVE-2020-12427
HIGHCVSS 8.8/10EPSS 0.45%
Last modified
CVE-2020-12427 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.
Description
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Westerndigital | Wd Discovery | < 3.8.229 |
References
- https://support.wdc.com/downloads.aspx?g=907&lang=enVendor Advisory
- https://support.wdc.com/downloads.aspx?g=907&lang=enVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-12427?
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
How severe is CVE-2020-12427?
CVE-2020-12427 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.45% probability of exploitation in the next 30 days.
How do I fix CVE-2020-12427?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-12421When performing add-on updates, certificate chains terminati…6.5
- CVE-2020-12422In non-standard configurations, a JPEG image created by Java…8.8
- CVE-2020-12423When the Windows DLL "webauthn.dll" was missing from the Ope…7.8
- CVE-2020-12424When constructing a permission prompt for WebRTC, a URI was …6.5
- CVE-2020-12425Due to confusion processing a hyphen character in Date.parse…6.5
- CVE-2020-12426Mozilla developers and community members reported memory saf…8.8
- CVE-2020-12429Online Course Registration 2.0 has multiple SQL injections t…9.8
- CVE-2020-1243<p>A denial of service vulnerability exists when Microsoft H…7.8
- CVE-2020-12430An issue was discovered in qemuDomainGetStatsIOThread in qem…6.5
- CVE-2020-12431A Windows privilege change issue was discovered in Splashtop…6.6
- CVE-2020-12432The WOPI API integration for Vereign Collabora CODE through …6.1
- CVE-2020-12438An XSS vulnerability exists in the banners.php page of PHP-F…5.4
Are you affected by CVE-2020-12427?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
