nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-36330 CVE-2022-36330
LOW
Buffer Overflow Vulnerability in Western Digital My Cloud Home and ibi devices
Record summary
CVE-2022-36330 has a selected CVSS score of 1.9 (low).
Description
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | Before 9.4.0-191 | affected |
My Cloud Home and My Cloud Home DuoBrowse Western Digital / My Cloud Home and My Cloud Home DuoDefault status: unaffected | CVE List | Before 9.4.0-191 | affected |
References
2westerndigital.com
https://www.westerndigital.com/support/product-security/wdc-23003-western-digital-my-cloud-home-my-cloud-home-duo-and-sandisk-ibi-firmware-version-9-4-0-191