Lucene search

K
cve[email protected]CVE-2022-29837
HistoryDec 01, 2022 - 5:15 p.m.

CVE-2022-29837

2022-12-0117:15:11
CWE-22
web.nvd.nist.gov
17
cve-2022-29837
path traversal
vulnerability
western-digital
my cloud home
my cloud home duo
sandisk
ibi
zip
code execution

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.0%

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

Affected configurations

NVD
Node
westerndigitalmy_cloud_homeMatch-
AND
westerndigitalmy_cloud_home_firmwareRange<8.12.0-178
Node
westerndigitalmy_cloud_home_duoMatch-
AND
westerndigitalmy_cloud_home_duo_firmwareRange<8.12.0-178
Node
westerndigitalsandisk_ibiMatch-
AND
westerndigitalsandisk_ibi_firmwareRange<8.12.0-178

CNA Affected

[
  {
    "vendor": "Western Digital",
    "product": "My Cloud Home",
    "versions": [
      {
        "version": "My Cloud Home ",
        "status": "affected",
        "lessThan": "8.12.0-178",
        "versionType": "custom"
      },
      {
        "version": "My Cloud Home Duo",
        "status": "affected",
        "lessThan": "8.12.0-178",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Linux"
    ]
  },
  {
    "vendor": "SanDisk",
    "product": "ibi",
    "versions": [
      {
        "version": "ibi",
        "status": "affected",
        "lessThan": "8.12.0-178",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Linux"
    ]
  }
]

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

7.6 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.0%

Related for CVE-2022-29837