Lucene search

K
cvelistWDC PSIRTCVELIST:CVE-2022-29837
HistoryDec 01, 2022 - 12:00 a.m.

CVE-2022-29837 Path traversal Vulnerability in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi Devices

2022-12-0100:00:00
CWE-22
WDC PSIRT
www.cve.org
cve-2022-29837
path traversal
installation of custom zip packages
overwrite system files
code execution

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

CNA Affected

[
  {
    "vendor": "Western Digital",
    "product": "My Cloud Home",
    "versions": [
      {
        "version": "My Cloud Home ",
        "status": "affected",
        "lessThan": "8.12.0-178",
        "versionType": "custom"
      },
      {
        "version": "My Cloud Home Duo",
        "status": "affected",
        "lessThan": "8.12.0-178",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Linux"
    ]
  },
  {
    "vendor": "SanDisk",
    "product": "ibi",
    "versions": [
      {
        "version": "ibi",
        "status": "affected",
        "lessThan": "8.12.0-178",
        "versionType": "custom"
      }
    ],
    "platforms": [
      "Linux"
    ]
  }
]

4.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

7.9 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Related for CVELIST:CVE-2022-29837