CVE Published: 12/06/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: WDC PSIRT |
Vendor: Western Digital |
Product: My Cloud OS 5 Status : PUBLISHED
CVE-2022-36331 Description
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data.
This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
Metrics
CVSS Version: 3.1 |
Base Score: 10 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H