A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-28104 | A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters. |
Fixes
Solution
Update your My Cloud device to firmware version 5.19.117.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WDC PSIRT
Published:
Updated: 2024-08-03T03:28:43.023Z
Reserved: 2022-01-10T00:00:00
Link: CVE-2022-22993
No data.
Status : Modified
Published: 2022-01-28T20:15:12.763
Modified: 2024-11-21T06:47:45.773
Link: CVE-2022-22993
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD