CVE-2022-22992

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:westerndigital:my_cloud_os:*:*:*:*:*:*:*:*
OR cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:-:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:wd_cloud:-:*:*:*:*:*:*:*

History

11 Jul 2023, 20:21

Type Values Removed Values Added
CWE CWE-77 CWE-116

Information

Published : 2022-01-28 20:15

Updated : 2024-02-28 18:48


NVD link : CVE-2022-22992

Mitre link : CVE-2022-22992

CVE.ORG link : CVE-2022-22992


JSON object : View

Products Affected

westerndigital

  • my_cloud_pr4100
  • my_cloud_ex4100
  • my_cloud_dl2100
  • my_cloud_pr2100
  • my_cloud_ex2100
  • my_cloud
  • my_cloud_ex2_ultra
  • my_cloud_mirror_gen_2
  • my_cloud_dl4100
  • my_cloud_os
  • wd_cloud
CWE
CWE-116

Improper Encoding or Escaping of Output