CVE Published: 01/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: WDC PSIRT |
Vendor: Western Digital |
Product: My Cloud Home Status : PUBLISHED
CVE-2022-29837 Description
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.
Metrics
CVSS Version: 3.1 |
Base Score: 4.7 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* LOW User Interaction (UI)* NONE Scope (S)* UNCHANGED