PT-2023-3277 · Sandisk+1 · Sandisk Ibi+3

·

CVE-2022-36331

·

Publicado

2023-03-23

·

Atualizado

2023-06-21

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud versions prior to 5.25.132 My Cloud Home and My Cloud Home Duo versions prior to 8.13.1-102 SanDisk ibi versions prior to 8.13.1-102
Description The issue is related to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This is due to an authentication bypass vulnerability, which can be exploited by a remote attacker to access user data and potentially execute arbitrary code.
Recommendations For Western Digital My Cloud versions prior to 5.25.132, update to version 5.25.132 or later to resolve the issue. For My Cloud Home and My Cloud Home Duo versions prior to 8.13.1-102, update to version 8.13.1-102 or later to resolve the issue. For SanDisk ibi versions prior to 8.13.1-102, update to version 8.13.1-102 or later to resolve the issue. As a temporary workaround, consider restricting access to the devices until a patch is applied.

Correção

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03408
CVE-2022-36331
ZDI-23-846
ZDI-23-847

Produtos afetados

My Cloud Home
My Cloud Home Duo
Sandisk Ibi
Western Digital My Cloud