nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-22989 CVE-2022-22989
CRITICAL
Pre-authenticated stack overflow vulnerability on FTP Service
Record summary
CVE-2022-22989 has a selected CVSS score of 9.8 (critical).
Description
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | My Cloud OS 5 to < 5.19.117 | affected |
References
2westerndigital.com
https://www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117