CVE-2022-22994
Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability on Western Digital My Cloud devices.
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.
Se ha detectado una vulnerabilidad de ejecución de código remota en los dispositivos My Cloud de Western Digital donde un atacante podía engañar a un dispositivo NAS para cargar mediante una llamada HTTP no segura. Esto era el resultado de una verificación insuficiente de las llamadas al dispositivo. La vulnerabilidad fue abordada al deshabilitar la comprobación de la conectividad a Internet mediante HTTP
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the ConnectivityService service. The issue results from the lack of proper authentication of data received via HTTP. An attacker can leverage this vulnerability to execute code in the context of root.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-10 CVE Reserved
- 2022-01-28 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-345: Insufficient Verification of Data Authenticity
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.zerodayinitiative.com/advisories/ZDI-22-349 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117 | 2022-03-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Search vendor "Westerndigital" for product "My Cloud" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Dl2100 Search vendor "Westerndigital" for product "My Cloud Dl2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Dl4100 Search vendor "Westerndigital" for product "My Cloud Dl4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex2 Ultra Search vendor "Westerndigital" for product "My Cloud Ex2 Ultra" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex2100 Search vendor "Westerndigital" for product "My Cloud Ex2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex4100 Search vendor "Westerndigital" for product "My Cloud Ex4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Mirror Gen 2 Search vendor "Westerndigital" for product "My Cloud Mirror Gen 2" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Pr2100 Search vendor "Westerndigital" for product "My Cloud Pr2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Pr4100 Search vendor "Westerndigital" for product "My Cloud Pr4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.19.117 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.19.117" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | Wd Cloud Search vendor "Westerndigital" for product "Wd Cloud" | - | - |
Safe
|