CVE-2022-36328
Path Traversal Vulnerability leading to an arbitrary file read in Western Digital devices
Record summary
CVE-2022-36328 has a selected CVSS score of 5.8 (medium).
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This can only be exploited once an attacker gains root privileges on the devices using an authentication bypass issue or another vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 9.4.0-191 | affected |
My Cloud Home and My Cloud Home DuoBrowse Western Digital / My Cloud Home and My Cloud Home DuoDefault status: unaffected | CVE List | Before 9.4.0-191 | affected |
My Cloud OS 5Browse Western Digital / My Cloud OS 5Default status: unaffected | CVE List | Before 5.26.202 | affected |