Description
Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.
Published: 2022-07-12
Score: 6.8 Medium
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

My Cloud Home devices have been automatically updated to resolve this vulnerability

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-28108 Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03097}

epss

{'score': 0.01742}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01757}

epss

{'score': 0.03097}


Subscriptions

Linux Linux Kernel
Westerndigital My Cloud Home My Cloud Home Duo My Cloud Home Duo Firmware My Cloud Home Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2024-08-03T03:28:42.830Z

Reserved: 2022-01-10T00:00:00.000Z

Link: CVE-2022-22997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-12T21:15:09.393

Modified: 2024-11-21T06:47:46.327

Link: CVE-2022-22997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses