PT-2023-12986 · Western Digital · Western Digital My Cloud Os 5
S_N_T
+1
·
Published
2023-05-10
·
Updated
2023-06-19
·
CVE-2022-29840
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Western Digital My Cloud OS 5 versions prior to 5.26.202
Description
A Server-Side Request Forgery (SSRF) issue was identified, which could allow a rogue server on the local network to modify its URL to point back to the loopback adapter. This could potentially exploit other vulnerabilities on the local server.
Recommendations
For Western Digital My Cloud OS 5 versions prior to 5.26.202, update to version 5.26.202 or later to resolve the issue. As a temporary workaround, consider restricting access to the local server to minimize the risk of exploitation.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Western Digital My Cloud Os 5