Use of a broken or risky cryptographic algorithm in WD Discovery for Mac and WD Discovery for Windows - CVE-2022-29835
Published: September 20, 2022
Vulnerability identifier: #VU67480
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29835
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the use of a hashing algorithm that is not collision-free. A remote attacker can create forged certificate signatures and gain access to sensitive information.
Affected software
WD Discovery for Mac
WD Discovery for Windows
WD Discovery for Windows
How to mitigate CVE-2022-29835
Install updates from vendor's website.
WD Discovery for Mac - update to 4.4.396
WD Discovery for Windows - update to 4.4.396
WD Discovery for Windows - update to 4.4.396