← Back

CVE-2022-29837

nvd nist
Published: Dec 1, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

Affected (3)

3 products
My Cloud Home Firmware
My Cloud Home Duo Firmware
Sandisk Ibi Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.12.0-178
Running on/withPlatform Versions
Westerndigital
My Cloud Home
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.12.0-178
Running on/withPlatform Versions
Westerndigital
My Cloud Home Duo
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.12.0-178
Running on/withPlatform Versions
Westerndigital
Sandisk Ibi
All versions

Timeline

No history available yet.