CVE-2022-36331
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.59% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-290
- Affected
- westerndigital/my cloud pr2100 firmware · westerndigital/my cloud pr4100 firmware · westerndigital/my cloud ex4100 firmware · westerndigital/my cloud ex2 ultra firmware · westerndigital/my cloud mirror g2 firmware · westerndigital/my cloud dl2100 firmware · westerndigital/my cloud dl4100 firmware · westerndigital/my cloud ex2100 firmware · westerndigital/my cloud home firmware · westerndigital/my cloud home duo firmware · westerndigital/sandisk ibi firmware · westerndigital/my cloud firmware
- Source
- psirt@wdc.com
References
- https://https://www.westerndigital.com/support/product-security/wdc-22020-my-cloud-os-5-my-cloud-home-ibi-firmware-updateBroken Link
- https://www.westerndigital.com/support/product-security/wdc-22020-my-cloud-os-5-my-cloud-home-ibi-firmware-updateVendor Advisory
- https://https://www.westerndigital.com/support/product-security/wdc-22020-my-cloud-os-5-my-cloud-home-ibi-firmware-updateBroken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.