CVE-2022-29837

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/12/2022
Last modified:
06/12/2022

Description

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:westerndigital:my_cloud_home_firmware:*:*:*:*:*:*:*:* 8.12.0-178 (excluding)
cpe:2.3:h:westerndigital:my_cloud_home:-:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:my_cloud_home_duo_firmware:*:*:*:*:*:*:*:* 8.12.0-178 (excluding)
cpe:2.3:h:westerndigital:my_cloud_home_duo:-:*:*:*:*:*:*:*
cpe:2.3:o:westerndigital:sandisk_ibi_firmware:*:*:*:*:*:*:*:* 8.12.0-178 (excluding)
cpe:2.3:h:westerndigital:sandisk_ibi:-:*:*:*:*:*:*:*