CVE-2022-22992

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:westerndigital:my_cloud_os:*:*:*:*:*:*:*:*
OR cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:-:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:wd_cloud:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:47

Type Values Removed Values Added
CVSS v2 : 10.0
v3 : 9.8
v2 : 10.0
v3 : 7.8
References () https://www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117 - Vendor Advisory () https://www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117 - Vendor Advisory

11 Jul 2023, 20:21

Type Values Removed Values Added
CWE CWE-77 CWE-116

Information

Published : 2022-01-28 20:15

Updated : 2024-11-21 06:47


NVD link : CVE-2022-22992

Mitre link : CVE-2022-22992

CVE.ORG link : CVE-2022-22992


JSON object : View

Products Affected

westerndigital

  • my_cloud_dl4100
  • my_cloud_ex2_ultra
  • my_cloud_pr4100
  • my_cloud_mirror_gen_2
  • my_cloud_os
  • my_cloud_dl2100
  • my_cloud_pr2100
  • my_cloud_ex2100
  • my_cloud
  • wd_cloud
  • my_cloud_ex4100
CWE
CWE-116

Improper Encoding or Escaping of Output