PT-2023-13477 · Sandisk+1 · Sandisk Ibi+1

CVE-2022-36330

·

Publicado

2023-05-09

·

Atualizado

2023-05-22

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud Home versions prior to 9.4.0-191 Western Digital My Cloud Home Duo versions prior to 9.4.0-191 SanDisk ibi versions prior to 9.4.0-191
Description A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability.
Recommendations For Western Digital My Cloud Home versions prior to 9.4.0-191, update to version 9.4.0-191 or later. For Western Digital My Cloud Home Duo versions prior to 9.4.0-191, update to version 9.4.0-191 or later. For SanDisk ibi versions prior to 9.4.0-191, update to version 9.4.0-191 or later.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-36330

Produtos afetados

Sandisk Ibi
Western Digital My Cloud Home