CVE-2022-22988

HIGH

File System - Info Disclosure

Title source: llm
STIX 2.1

Description

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated access to the device.

References (1)

Core 1

Scores

CVSS v3 7.7
EPSS 0.0015
EPSS Percentile 34.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-732 CWE-275
Status published
Products (1)
westerndigital/edgerover < 1.5.0-576 (2 CPE variants)
Published Jan 13, 2022
Tracked Since Feb 18, 2026