Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-34156 Improper Authentication vulnerability in the encrypted volumes and auto mount features of Western Digital My Cloud devices allows insecure direct access to the drive information in the case of a device reset. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.
Fixes

Solution

To take advantage of the latest security fixes, Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.


Workaround

No workaround given by the vendor.

History

Wed, 23 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2025-04-23T14:15:52.043Z

Reserved: 2022-04-27T00:00:00.000Z

Link: CVE-2022-29838

cve-icon Vulnrichment

Updated: 2024-08-03T06:33:42.806Z

cve-icon NVD

Status : Modified

Published: 2022-12-09T18:15:18.517

Modified: 2024-11-21T06:59:47.333

Link: CVE-2022-29838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.