10

CVE-2022-22992

Command Injection Remote Code Execution vulnerability on Western Digital My Cloud devices.

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Westerndigital ≫ My Cloud Os Version < 5.19.117
   Westerndigital ≫ My Cloud Version - SwEdition -
   Westerndigital ≫ My Cloud Dl2100 Version -
   Westerndigital ≫ My Cloud Dl4100 Version -
   Westerndigital ≫ My Cloud Ex2 Ultra Version -
   Westerndigital ≫ My Cloud Ex2100 Version -
   Westerndigital ≫ My Cloud Ex4100 Version -
   Westerndigital ≫ My Cloud Mirror Gen 2 Version -
   Westerndigital ≫ My Cloud Pr2100 Version -
   Westerndigital ≫ My Cloud Pr4100 Version -
   Westerndigital ≫ Wd Cloud Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.31% 0.811
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
psirt@wdc.com 7.8 1.4 5.8
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
CWE-116 Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

https://www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117
Vendor Advisory