7.5
CVE-2022-36329
- EPSS 0.09%
- Published 10.05.2023 20:15:09
- Last modified 21.11.2024 07:12:48
- Source psirt@wdc.com
- Teams watchlist Login
- Open Login
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
Data is provided by the National Vulnerability Database (NVD)
Westerndigital ≫ My Cloud Home Firmware Version < 9.4.0-191
Westerndigital ≫ My Cloud Home Duo Firmware Version < 9.4.0-191
Westerndigital ≫ Sandisk Ibi Firmware Version < 9.4.0-191
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.219 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
psirt@wdc.com | 4.4 | 0.8 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.