Lucene search

K
cve[email protected]CVE-2022-29844
HistoryJan 26, 2023 - 9:15 p.m.

CVE-2022-29844

2023-01-2621:15:33
CWE-22
CWE-23
web.nvd.nist.gov
20
2
cve-2022-29844
ftp
vulnerability
western digital
my cloud
os 5
firmware
nas
compromise
remote execution
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.4%

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.

Affected configurations

NVD
Node
westerndigitalmy_cloud_pr2100_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_pr2100Match-
Node
westerndigitalmy_cloud_pr4100_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_pr4100Match-
Node
westerndigitalmy_cloud_ex4100_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_ex4100Match-
Node
westerndigitalmy_cloud_ex2_ultra_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_ex2_ultraMatch-
Node
westerndigitalmy_cloud_mirror_g2_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_mirror_g2Match-
Node
westerndigitalmy_cloud_dl2100_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_dl2100Match-
Node
westerndigitalmy_cloud_dl4100_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_dl4100Match-
Node
westerndigitalmy_cloud_ex2100_firmwareRange<5.26.119
AND
westerndigitalmy_cloud_ex2100Match-

CNA Affected

[
  {
    "vendor": "Western Digital",
    "product": "My Cloud",
    "versions": [
      {
        "version": "My Cloud OS 5",
        "status": "affected",
        "lessThan": "5.26.119",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Linux"
    ]
  }
]

Social References

More

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.4%

Related for CVE-2022-29844