Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.

Published: 2023-05-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-34160 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.
History

Fri, 24 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Westerndigital My Cloud My Cloud Dl2100 My Cloud Dl4100 My Cloud Ex2100 My Cloud Ex2 Ultra My Cloud Ex4100 My Cloud Mirror G2 My Cloud Os My Cloud Pr2100 My Cloud Pr4100 Wd Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2025-01-24T21:00:19.549Z

Reserved: 2022-04-27T20:53:48.677Z

Link: CVE-2022-29842

cve-icon Vulnrichment

Updated: 2024-08-03T06:33:42.845Z

cve-icon NVD

Status : Modified

Published: 2023-05-10T21:15:08.867

Modified: 2024-11-21T06:59:47.857

Link: CVE-2022-29842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses