← Back

CVE-2022-29841

nvd nist
Published: May 10, 2023Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.

Affected (1)

My Cloud Os
Configuration A
1 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
From 5.02.104 to 5.26.119
Running on/withPlatform Versions
Westerndigital
My Cloud
All versions
Westerndigital
My Cloud Dl2100
All versions
Westerndigital
My Cloud Dl4100
All versions
Westerndigital
My Cloud Ex2100
All versions
Westerndigital
My Cloud Ex2 Ultra
All versions
Westerndigital
My Cloud Ex4100
All versions
Westerndigital
My Cloud Mirror G2
All versions
Westerndigital
My Cloud Pr2100
All versions
Westerndigital
My Cloud Pr4100
All versions
Westerndigital
Wd Cloud
All versions

Timeline

No history available yet.