Lucene search

K
cvelistWDC PSIRTCVELIST:CVE-2022-22988
HistoryJan 13, 2022 - 8:27 p.m.

CVE-2022-22988 Insecure file and directory permissions on EdgeRover

2022-01-1320:27:27
CWE-275
WDC PSIRT
www.cve.org
2
edgerover
file permissions
directory permissions
authenticated attacker
unauthorized access
cve-2022-22988

CVSS3

7.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

54.2%

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated access to the device.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Mac"
    ],
    "product": "EdgeRover",
    "vendor": "Western Digital",
    "versions": [
      {
        "lessThan": "1.5.0-576",
        "status": "affected",
        "version": "EdgeRover Mac Desktop App",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "EdgeRover",
    "vendor": "Western Digital",
    "versions": [
      {
        "lessThan": "1.5.0-576",
        "status": "affected",
        "version": "EdgeRover Windows Desktop App",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

54.2%

Related for CVELIST:CVE-2022-22988