← Back

CVE-2022-36330

nvd nist
Published: May 10, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 

Affected (3)

3 products
My Cloud Home Duo Firmware
Sandisk Ibi Firmware
My Cloud Home Firmware
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.4.0-191
Running on/withPlatform Versions
Westerndigital
My Cloud Home Duo
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.4.0-191
Running on/withPlatform Versions
Westerndigital
Sandisk Ibi
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 9.4.0-191
Running on/withPlatform Versions
Westerndigital
My Cloud Home
All versions

Timeline

No history available yet.