Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-34160 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
Fixes

Solution

Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.


Workaround

No workaround given by the vendor.

History

Fri, 24 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2025-01-24T21:00:19.549Z

Reserved: 2022-04-27T20:53:48.677Z

Link: CVE-2022-29842

cve-icon Vulnrichment

Updated: 2024-08-03T06:33:42.845Z

cve-icon NVD

Status : Modified

Published: 2023-05-10T21:15:08.867

Modified: 2024-11-21T06:59:47.857

Link: CVE-2022-29842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.