CVE-2022-36331
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data.
This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
Affected (12)
Products: Westerndigital: My Cloud Pr2100 Firmware, My Cloud Pr4100 Firmware, My Cloud Ex4100 Firmware, My Cloud Ex2 Ultra Firmware, My Cloud Mirror G2 Firmware, My Cloud Dl2100 Firmware, My Cloud Dl4100 Firmware, My Cloud Ex2100 Firmware, My Cloud Home Firmware, My Cloud Home Duo Firmware, Sandisk Ibi Firmware, My Cloud Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Pr2100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Pr4100 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Ex4100 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Ex2 Ultra | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Mirror G2 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Dl2100 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Dl4100 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Ex2100 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.13.1-102 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Home | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.13.1-102 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud Home Duo | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 8.13.1-102 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital Sandisk Ibi | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.25.132 |
| Running on/with | Platform Versions |
|---|---|
Westerndigital My Cloud | All versions |
References (3)
Source: psirt@wdc.com
Broken Link
Source: nvd@nist.gov
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Timeline
No history available yet.