PT-2023-13474 · Sandisk+1 · Sandisk Ibi+2

S_N_T

+1

·

Publicado

2023-05-18

·

Atualizado

2023-06-19

·

CVE-2022-36326

CVSS v3.1

4.9

Média

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud Home versions before 9.4.0-191 Western Digital My Cloud Home Duo versions before 9.4.0-191 SanDisk ibi versions before 9.4.0-191 Western Digital My Cloud OS 5 versions before 5.26.202
Description An uncontrolled resource consumption issue could arise by sending crafted requests to a service, consuming a large amount of memory and eventually resulting in the service being stopped and restarted. This issue requires the attacker to already have root privileges in order to exploit it.
Recommendations For Western Digital My Cloud Home versions before 9.4.0-191, update to version 9.4.0-191 or later. For Western Digital My Cloud Home Duo versions before 9.4.0-191, update to version 9.4.0-191 or later. For SanDisk ibi versions before 9.4.0-191, update to version 9.4.0-191 or later. For Western Digital My Cloud OS 5 versions before 5.26.202, update to version 5.26.202 or later.

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-36326
ZDI-23-851

Produtos afetados

Sandisk Ibi
Western Digital My Cloud Home
Western Digital My Cloud Os 5