CVE-2022-29844
medium · 6.7A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.
6.7
CVSS
36.4%
EPSS (exploit prob.)
98th
EPSS percentile
2023-01-26
Published
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-23CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| westerndigital | my_cloud_pr2100_firmware | < 5.26.119 |
| westerndigital | my_cloud_pr2100 | all versions |
| westerndigital | my_cloud_pr4100_firmware | < 5.26.119 |
| westerndigital | my_cloud_pr4100 | all versions |
| westerndigital | my_cloud_ex4100_firmware | < 5.26.119 |
| westerndigital | my_cloud_ex4100 | all versions |
| westerndigital | my_cloud_ex2_ultra_firmware | < 5.26.119 |
| westerndigital | my_cloud_ex2_ultra | all versions |
| westerndigital | my_cloud_mirror_g2_firmware | < 5.26.119 |
| westerndigital | my_cloud_mirror_g2 | all versions |
| westerndigital | my_cloud_dl2100_firmware | < 5.26.119 |
| westerndigital | my_cloud_dl2100 | all versions |
| westerndigital | my_cloud_dl4100_firmware | < 5.26.119 |
| westerndigital | my_cloud_dl4100 | all versions |
| westerndigital | my_cloud_ex2100_firmware | < 5.26.119 |
| westerndigital | my_cloud_ex2100 | all versions |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-29844