CVE Published: 10/05/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: WDC PSIRT |
Vendor: Western Digital |
Product: My Cloud Home and My Cloud Home Duo Status : PUBLISHED
CVE-2022-36329 Description
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
Metrics
CVSS Version: 3.1 |
Base Score: 4.4 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* LOW User Interaction (UI)* REQUIRED Scope (S)* UNCHANGED