Improper Authentication in Western Digital products - CVE-2022-22990

 

Improper Authentication in Western Digital products - CVE-2022-22990

Published: February 18, 2022


Vulnerability identifier: #VU60710
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22990
CWE-ID: CWE-287
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to incorrect string matching logic when accessing protected pages within the nasAdmin service. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.


Affected software

My Cloud PR2100
My Cloud PR4100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud Mirror Gen 2
My Cloud DL2100
My Cloud DL4100
My Cloud EX2100
WD My Cloud
My Cloud
My Cloud OS 5

How to mitigate CVE-2022-22990

Install updates from vendor's website.

My Cloud OS 5 - update to 5.19.117

External References

Related Security Bulletins