The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Netatalk
Subscribe
|
Netatalk
Subscribe
|
|
Westerndigital
Subscribe
|
My Cloud
Subscribe
My Cloud Dl2100
Subscribe
My Cloud Dl2100 Firmware
Subscribe
My Cloud Dl4100
Subscribe
My Cloud Dl4100 Firmware
Subscribe
My Cloud Ex2100
Subscribe
My Cloud Ex2100 Firmware
Subscribe
My Cloud Ex2 Ultra
Subscribe
My Cloud Ex2 Ultra Firmware
Subscribe
My Cloud Ex4100
Subscribe
My Cloud Ex4100 Firmware
Subscribe
My Cloud Firmware
Subscribe
My Cloud Home
Subscribe
My Cloud Home Firmware
Subscribe
My Cloud Mirror Gen 2
Subscribe
My Cloud Mirror Gen 2 Firmware
Subscribe
My Cloud Pr2100
Subscribe
My Cloud Pr2100 Firmware
Subscribe
My Cloud Pr4100
Subscribe
My Cloud Pr4100 Firmware
Subscribe
Wd Cloud
Subscribe
Wd Cloud Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3706-1 | netatalk security update |
Debian DLA |
DLA-3968-1 | netatalk security update |
EUVD |
EUVD-2022-28106 | The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code. |
Ubuntu USN |
USN-6786-1 | Netatalk vulnerabilities |
Fixes
Solution
To take advantage of the latest security fixes, Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WDC PSIRT
Published:
Updated: 2025-11-03T21:45:48.606Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-22995
No data.
Status : Modified
Published: 2022-03-25T23:15:08.410
Modified: 2025-11-03T22:15:55.473
Link: CVE-2022-22995
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN