CVE-2022-22991

HIGH

Western Digital My Cloud OS < 5.19.117 - OS Command Injection via DNS Spoofing

Title source: llm
STIX 2.1

Description

A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity using HTTP.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0133
EPSS Percentile 67.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
westerndigital/my_cloud_os < 5.19.117
Published Jan 13, 2022
Tracked Since Feb 18, 2026