Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data.
This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.

Project Subscriptions

Vendors Products
Westerndigital Subscribe
My Cloud Subscribe
My Cloud Dl2100 Subscribe
My Cloud Dl2100 Firmware Subscribe
My Cloud Dl4100 Subscribe
My Cloud Dl4100 Firmware Subscribe
My Cloud Ex2100 Subscribe
My Cloud Ex2100 Firmware Subscribe
My Cloud Ex2 Ultra Subscribe
My Cloud Ex2 Ultra Firmware Subscribe
My Cloud Ex4100 Subscribe
My Cloud Ex4100 Firmware Subscribe
My Cloud Firmware Subscribe
My Cloud Home Subscribe
My Cloud Home Duo Subscribe
My Cloud Home Duo Firmware Subscribe
My Cloud Home Firmware Subscribe
My Cloud Mirror G2 Subscribe
My Cloud Mirror G2 Firmware Subscribe
My Cloud Pr2100 Subscribe
My Cloud Pr2100 Firmware Subscribe
My Cloud Pr4100 Subscribe
My Cloud Pr4100 Firmware Subscribe
Sandisk Ibi Subscribe
Sandisk Ibi Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-39047 Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
Fixes

Solution

All My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices have been or will be automatically updated to the latest firmware version. Cloud access will not be available until your My Cloud Home/My Cloud Home Duo/SanDisk ibi device has been updated to firmware version 8.13.1-102 or above. Please refer to this KBA https://support-en.wd.com/app/answers/detailweb/a_id/50563 . Users of other My Cloud devices should promptly update to the latest firmware by clicking the firmware update notification to receive the latest security fixes. Cloud access will not be available until your My Cloud device has been updated to firmware version 5.25.132 or above. Please refer to this KBA https://support-en.wd.com/app/answers/detailweb/a_id/50564 .


Workaround

No workaround given by the vendor.

History

Fri, 03 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2025-01-03T14:48:13.386Z

Reserved: 2022-07-20T13:57:56.405Z

Link: CVE-2022-36331

cve-icon Vulnrichment

Updated: 2024-08-03T10:00:04.251Z

cve-icon NVD

Status : Modified

Published: 2023-06-12T18:15:09.747

Modified: 2024-11-21T07:12:48.703

Link: CVE-2022-36331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses