CVE Published: 13/01/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: WDC PSIRT |
Vendor: Western Digital |
Product: My Cloud Status : PUBLISHED
CVE-2022-22990 Description
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* NONE User Interaction (UI)* NONE Scope (S)* CHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* NONE
Weakness Enumeration (CWE)
CWE-ID: CWE-287 CWE Name: CWE-287 Improper Authentication Source: Western Digital
Common Attack Pattern Enumeration and Classification (CAPEC)