CVE-2022-29837
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.12.0-178 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Home | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.12.0-178 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Home Duo | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.12.0-178 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital Sandisk Ibi | All versions |
References (2)
Source: psirt@wdc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.