10

CVE-2022-22995

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

Data is provided by the National Vulnerability Database (NVD)
WesterndigitalMy Cloud Pr2100 Firmware Version < 5.19.117
   WesterndigitalMy Cloud Pr2100 Version-
WesterndigitalMy Cloud Pr4100 Firmware Version < 5.19.117
   WesterndigitalMy Cloud Pr4100 Version-
WesterndigitalMy Cloud Ex4100 Firmware Version < 5.19.117
   WesterndigitalMy Cloud Ex4100 Version-
WesterndigitalMy Cloud Dl2100 Firmware Version < 5.19.117
   WesterndigitalMy Cloud Dl2100 Version-
WesterndigitalMy Cloud Dl4100 Firmware Version < 5.19.117
   WesterndigitalMy Cloud Dl4100 Version-
WesterndigitalMy Cloud Ex2100 Firmware Version < 5.19.117
   WesterndigitalMy Cloud Ex2100 Version-
WesterndigitalMy Cloud Firmware Version < 5.19.117
   WesterndigitalMy Cloud Version-
WesterndigitalWd Cloud Firmware Version < 5.19.117
   WesterndigitalWd Cloud Version-
WesterndigitalMy Cloud Home Firmware Version < 7.16-220
   WesterndigitalMy Cloud Home Version-
NetatalkNetatalk Version < 3.1.18
FedoraprojectFedora Version37
FedoraprojectFedora Version38
FedoraprojectFedora Version39
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.18% 0.397
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
psirt@wdc.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.