HomeWesterndigitalCVE-2021-33205

CVE-2021-33205

HIGH
8.8CVSS
Published: 2021-06-11
Updated: 2024-11-21
AI Analysis

Description

Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library and stealing user credentials.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
NVD-CWE-noinfo

Metadata

Primary Vendor
WESTERNDIGITAL
Published
6/11/2021
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

westerndigital : edgerover

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-33205 | HIGH Severity | CVEDatabase.com | CVEDatabase.com