The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
|
History
21 Nov 2024, 06:47
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 10.0 |
References | () https://lists.debian.org/debian-lts-announce/2024/01/msg00000.html - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/55ROUJI22SHZX5EM23QAILZHI67EZQKW/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5CZZLFOTUP3QYHGHSDUNENGSLPJ6KGO/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO34FWOIJI6V6PH2XY52WNBBARVWPJG2/ - Mailing List | |
References | () https://security.gentoo.org/glsa/202311-02 - Issue Tracking, Third Party Advisory | |
References | () https://www.westerndigital.com/support/product-security/wdc-22005-netatalk-security-vulnerabilities - Vendor Advisory |
04 Jan 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Dec 2023, 15:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5CZZLFOTUP3QYHGHSDUNENGSLPJ6KGO/ - Mailing List | |
References | (GENTOO) https://security.gentoo.org/glsa/202311-02 - Issue Tracking, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO34FWOIJI6V6PH2XY52WNBBARVWPJG2/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/55ROUJI22SHZX5EM23QAILZHI67EZQKW/ - Mailing List | |
First Time |
Netatalk
Netatalk netatalk Fedoraproject fedora Fedoraproject |
|
CPE | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:* |
07 Nov 2023, 03:44
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
03 Nov 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Nov 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Oct 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2022-03-25 23:15
Updated : 2024-11-21 06:47
NVD link : CVE-2022-22995
Mitre link : CVE-2022-22995
CVE.ORG link : CVE-2022-22995
JSON object : View
Products Affected
westerndigital
- my_cloud_home_firmware
- my_cloud_dl4100
- my_cloud_ex2_ultra
- my_cloud
- my_cloud_home
- my_cloud_firmware
- my_cloud_pr4100_firmware
- my_cloud_ex4100_firmware
- my_cloud_dl4100_firmware
- my_cloud_mirror_gen_2
- wd_cloud
- my_cloud_ex4100
- my_cloud_pr2100_firmware
- my_cloud_dl2100_firmware
- my_cloud_ex2100
- my_cloud_mirror_gen_2_firmware
- my_cloud_ex2100_firmware
- my_cloud_ex2_ultra_firmware
- my_cloud_dl2100
- my_cloud_pr2100
- my_cloud_pr4100
- wd_cloud_firmware
fedoraproject
- fedora
netatalk
- netatalk
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')