Westerndigital
Westerndigital MY Cloud Home Firmware: vulnerabilidades y CVE
Westerndigital MY Cloud Home Firmware tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-22819 | Media (4.9) | 0.82% | — | 5 feb 2024 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was… |
| CVE-2023-22817 | Media (5.5) | 0.24% | — | 5 feb 2024 | Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to… |
| CVE-2022-36331 | Alta (7.5) | 0.59% | — | 12 jun 2023 | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects… |
| CVE-2022-36328 | Media (4.9) | 0.77% | — | 18 may 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords,… |
| CVE-2022-36327 | Crítica (9.8) | 1.5% | — | 18 may 2023 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code… |
| CVE-2022-36326 | Media (4.9) | 0.57% | — | 18 may 2023 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was… |
| CVE-2022-36329 | Alta (7.5) | 0.30% | — | 10 may 2023 | An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This… |
| CVE-2022-36330 | Alta (8.1) | 0.56% | — | 10 may 2023 | A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An… |
| CVE-2022-29837 | Alta (7.8) | 0.20% | — | 1 dic 2022 | A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files.… |
| CVE-2022-29836 | Media (4.3) | 0.33% | — | 9 nov 2022 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Western Digital My Cloud Home; My Cloud Home Duo; and SanDisk ibi devices that could allow… |
| CVE-2022-23006 | Media (6.7) | 0.31% | — | 27 sept 2022 | A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version… |
| CVE-2022-22998 | Alta (7.5) | 0.80% | — | 12 jul 2022 | Implemented protections on AWS credentials that were not properly protected. |
| CVE-2022-22997 | Crítica (9.8) | 1.5% | — | 12 jul 2022 | Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices. |
| CVE-2022-22995 | Crítica (9.8) | 2.7% | — | 25 mar 2022 | The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code. |
Otros productos de Westerndigital
MY Cloud OS · 18MY Cloud Home DUO Firmware · 13MY Cloud Firmware · 12Sandisk IBI Firmware · 11MY Cloud Pr4100 Firmware · 11MY Cloud Dl2100 Firmware · 10MY Cloud EX2 Ultra Firmware · 10MY Cloud Dl4100 Firmware · 10MY Cloud Ex2100 Firmware · 10MY Cloud Ex4100 Firmware · 10MY Cloud Pr2100 Firmware · 9MY Cloud OS 5 · 8