CVE-2022-22994

HIGH

Western Digital My Cloud OS < 5.19.117 - Remote Code Execution via Unsecured HTTP Call

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-22-349/

Scores

CVSS v3 8.8
EPSS 0.0174
EPSS Percentile 74.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-345
Status published
Products (1)
westerndigital/my_cloud_os < 5.19.117
Published Jan 28, 2022
Tracked Since Feb 18, 2026