TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-29837

MEDIUM
4.7

Beschreibung

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

CVE Details

CVSS v3.1 Bewertung4.7
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorLOCAL
KomplexitatHIGH
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht12/1/2022
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

westerndigital:my_cloud_homewesterndigital:my_cloud_home_duowesterndigital:my_cloud_home_duo_firmwarewesterndigital:my_cloud_home_firmwarewesterndigital:sandisk_ibiwesterndigital:sandisk_ibi_firmware

Schwachen (CWE)

CWE-22CWE-22

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.