PT-2022-15767 · Western Digital · My Cloud Home

Published

2022-07-12

·

Updated

2022-07-20

·

CVE-2022-22997

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions My Cloud Home devices (affected versions not specified)
Description A remote code execution issue was addressed by resolving a command injection vulnerability and securing an AWS S3 bucket. This vulnerability potentially allowed an attacker to execute unsigned code on the devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22997

Affected Products

My Cloud Home