9.8

CVE-2022-22995

Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in Netatalk

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Westerndigital ≫ My Cloud Pr2100 Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Pr2100 Version -
Westerndigital ≫ My Cloud Pr4100 Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Pr4100 Version -
Westerndigital ≫ My Cloud Ex4100 Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Ex4100 Version -
Westerndigital ≫ My Cloud Dl2100 Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Dl2100 Version -
Westerndigital ≫ My Cloud Dl4100 Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Dl4100 Version -
Westerndigital ≫ My Cloud Ex2100 Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Ex2100 Version -
Westerndigital ≫ My Cloud Firmware Version < 5.19.117
   Westerndigital ≫ My Cloud Version -
Westerndigital ≫ Wd Cloud Firmware Version < 5.19.117
   Westerndigital ≫ Wd Cloud Version -
Westerndigital ≫ My Cloud Home Firmware Version < 7.16-220
   Westerndigital ≫ My Cloud Home Version -
Netatalk ≫ Netatalk Version < 3.1.18
Fedoraproject ≫ Fedora Version 37
Fedoraproject ≫ Fedora Version 38
Fedoraproject ≫ Fedora Version 39
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.76% 0.85
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
psirt@wdc.com 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://security.gentoo.org/glsa/202311-02
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2024/01/msg00000.html
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/55ROUJI22SHZX5EM23QAILZHI67EZQKW/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5CZZLFOTUP3QYHGHSDUNENGSLPJ6KGO/
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO34FWOIJI6V6PH2XY52WNBBARVWPJG2/
Mailing List
https://www.westerndigital.com/support/product-security/wdc-22005-netatalk-security-vulnerabilities
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2024/11/msg00026.html