← Back

CVE-2022-22992

nvd nist
Published: Jan 28, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.

Affected (1)

My Cloud Os
Configuration A
1 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Before 5.19.117
Running on/withPlatform Versions
Westerndigital
My Cloud
All versions
Westerndigital
My Cloud Dl2100
All versions
Westerndigital
My Cloud Dl4100
All versions
Westerndigital
My Cloud Ex2100
All versions
Westerndigital
My Cloud Ex2 Ultra
All versions
Westerndigital
My Cloud Ex4100
All versions
Westerndigital
My Cloud Mirror Gen 2
All versions
Westerndigital
My Cloud Pr2100
All versions
Westerndigital
My Cloud Pr4100
All versions
Westerndigital
Wd Cloud
All versions

Timeline

No history available yet.