← Back

CVE-2022-22994

nvd nist
Published: Jan 28, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.

Affected (1)

My Cloud Os
Configuration A
1 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Before 5.19.117
Running on/withPlatform Versions
Westerndigital
My Cloud
All versions
Westerndigital
My Cloud Dl2100
All versions
Westerndigital
My Cloud Dl4100
All versions
Westerndigital
My Cloud Ex2100
All versions
Westerndigital
My Cloud Ex2 Ultra
All versions
Westerndigital
My Cloud Ex4100
All versions
Westerndigital
My Cloud Mirror Gen 2
All versions
Westerndigital
My Cloud Pr2100
All versions
Westerndigital
My Cloud Pr4100
All versions
Westerndigital
Wd Cloud
All versions

References (4)

Source: psirt@wdc.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.