Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-22992


A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.


Published

2022-01-28T20:15:12.707

Last Modified

2024-11-21T06:47:45.647

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-116

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System westerndigital my_cloud_os < 5.19.117 Yes
Hardware westerndigital my_cloud - No
Hardware westerndigital my_cloud_dl2100 - No
Hardware westerndigital my_cloud_dl4100 - No
Hardware westerndigital my_cloud_ex2_ultra - No
Hardware westerndigital my_cloud_ex2100 - No
Hardware westerndigital my_cloud_ex4100 - No
Hardware westerndigital my_cloud_mirror_gen_2 - No
Hardware westerndigital my_cloud_pr2100 - No
Hardware westerndigital my_cloud_pr4100 - No
Hardware westerndigital wd_cloud - No

References