PT-2022-15768 · Western Digital · Edgerover

Published

2022-03-21

·

Updated

2022-07-20

·

CVE-2022-22998

CVSS v3.1

8.0

High

VectorAV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Western Digital EdgeRover versions prior to 1.5.1-594
Description A critical error has been discovered in Western Digital's EdgeRover desktop application, which poses a threat of privilege escalation in Windows and macOS, potentially allowing attackers to access confidential information and perform DoS attacks. The vulnerability is an error that allows unauthorized access to restricted directories and files. It is estimated that a significant number of people use EdgeRover for data management, given Western Digital's success as a manufacturer and retailer of digital data storage products.
Recommendations To resolve the issue, update Western Digital EdgeRover to version 1.5.1-594 or later. As a temporary workaround, consider using the default file manager that comes with your operating system to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22998

Affected Products

Edgerover