CVE-2022-36330
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability.
This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
Affected (3)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.4.0-191 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Home Duo | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.4.0-191 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital Sandisk Ibi | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.4.0-191 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Home | All versions |
References (2)
Source: psirt@wdc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.