CVE-2022-29839
Remote Backups Application Discloses Stored Credentials
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.
Vulnerabilidad de credenciales insuficientemente protegidas en la aplicación de copias de seguridad remotas en dispositivos Western Digital My Cloud que podría permitir que un atacante que haya obtenido acceso a un endpoint relevante use esa información para acceder a datos protegidos. Este problema afecta: Versiones de Western Digital My Cloud My Cloud anteriores a la 5.25.124 en Linux.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-04-27 CVE Reserved
- 2022-12-09 CVE Published
- 2024-07-01 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Search vendor "Westerndigital" for product "My Cloud" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Dl2100 Search vendor "Westerndigital" for product "My Cloud Dl2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Dl4100 Search vendor "Westerndigital" for product "My Cloud Dl4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex2 Ultra Search vendor "Westerndigital" for product "My Cloud Ex2 Ultra" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex2100 Search vendor "Westerndigital" for product "My Cloud Ex2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Ex4100 Search vendor "Westerndigital" for product "My Cloud Ex4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Mirror G2 Search vendor "Westerndigital" for product "My Cloud Mirror G2" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Pr2100 Search vendor "Westerndigital" for product "My Cloud Pr2100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | My Cloud Pr4100 Search vendor "Westerndigital" for product "My Cloud Pr4100" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Westerndigital Search vendor "Westerndigital" | Wd Cloud Search vendor "Westerndigital" for product "Wd Cloud" | - | - |
Safe
|
Westerndigital Search vendor "Westerndigital" | My Cloud Os Search vendor "Westerndigital" for product "My Cloud Os" | < 5.25.124 Search vendor "Westerndigital" for product "My Cloud Os" and version " < 5.25.124" | - |
Affected
| in | Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | - | - |
Safe
|