A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28104 A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
Fixes

Solution

Update your My Cloud device to firmware version 5.19.117.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2024-08-03T03:28:43.023Z

Reserved: 2022-01-10T00:00:00

Link: CVE-2022-22993

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-01-28T20:15:12.763

Modified: 2024-11-21T06:47:45.773

Link: CVE-2022-22993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses