Western Digital Vulnerabilities and Affected Products
Vulnerabilities associated with Sweet B Library.
Products
Clear product- My Cloud14 vulnerabilities
- My Cloud OS 512 vulnerabilities
- My Cloud Home6 vulnerabilities
- My Cloud Home and My Cloud Home Duo6 vulnerabilities
- Sweet B Library4 vulnerabilities
- WD Discovery3 vulnerabilities
- My Cloud Home & Duo2 vulnerabilities
- My Cloud Home Web App2 vulnerabilities
- EdgeRover1 vulnerability
- My Cloud Home Duo1 vulnerability
- My Cloud Home Mobile App1 vulnerability
- My Cloud OS 5 Mobile App1 vulnerability
- My Cloud OS 5 Web App1 vulnerability
- My Cloud web app1 vulnerability
- my_book_live_firmware1 vulnerability
- my_cloud_pr4100_firmware1 vulnerability
- mycloud_nas1 vulnerability
- TV Live Hub1 vulnerability
- TV Media Player1 vulnerability
- WD Cloud web app1 vulnerability
- wd_my_book_live_firmware1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-23004MEDIUM | Algorithm incorrectly returning error and Invalid unreduced value written to output bufferWhen computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned from the library, and an invalid unreduced value is written to the output buffer. This may be leveraged by an attacker to cause an error scenario, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components. | CVSS5.3v3.1 | EPSS0.668% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-23003MEDIUM | Shared secret or Point multiplication of NIST P-256 points with X coordinate of zeroWhen computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output may cause an error when used in other operations. This may be leveraged by an attacker to cause an error scenario or incorrect choice of session key in applications which use the library, resulting in a limited denial of service for an individual user. The scope of imp… | CVSS5.3v3.1 | EPSS0.668% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-23002MEDIUM | Point Compression/Decompression of NIST P-256 points with X coordinate of zeroWhen compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting output is not properly reduced modulo the P-256 field prime and is invalid. The resulting output will cause an error when used in other operations. This may be leveraged by an attacker to cause an error scenario in applications which use the library, resulting in a limited denial of service for an individual user. The scope of impact cannot extend to other components. CWE-703Jul 29, 2022 | CVSS5.3v3.1 | EPSS0.668% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-23001MEDIUM | Sweet-B Library: Point compress/decompress using the wrong bit for signWhen compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user level privileges and no other user's assistance can exploit this vulnerability with only knowledge of the public key and the library. The resulting output may cause an error when used in other operations; for instance, verification of a valid signature under a decompressed public key may fail. This may be leveraged by an attacker to cause an error scen… CWE-682Jul 29, 2022 | CVSS5.3v3.1 | EPSS0.668% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |