PT-2023-12986 · Western Digital · Western Digital My Cloud Os 5

S_N_T

+1

·

Publicado

2023-05-10

·

Atualizado

2023-06-19

·

CVE-2022-29840

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud OS 5 versions prior to 5.26.202
Description A Server-Side Request Forgery (SSRF) issue was identified, which could allow a rogue server on the local network to modify its URL to point back to the loopback adapter. This could potentially exploit other vulnerabilities on the local server.
Recommendations For Western Digital My Cloud OS 5 versions prior to 5.26.202, update to version 5.26.202 or later to resolve the issue. As a temporary workaround, consider restricting access to the local server to minimize the risk of exploitation.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-29840
ZDI-23-850

Produtos afetados

Western Digital My Cloud Os 5