PT-2023-12986 · Western Digital · Western Digital My Cloud Os 5

S_N_T

+1

·

Published

2023-05-10

·

Updated

2023-06-19

·

CVE-2022-29840

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud OS 5 versions prior to 5.26.202
Description A Server-Side Request Forgery (SSRF) issue was identified, which could allow a rogue server on the local network to modify its URL to point back to the loopback adapter. This could potentially exploit other vulnerabilities on the local server.
Recommendations For Western Digital My Cloud OS 5 versions prior to 5.26.202, update to version 5.26.202 or later to resolve the issue. As a temporary workaround, consider restricting access to the local server to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-29840
ZDI-23-850

Affected Products

Western Digital My Cloud Os 5