Input validation error in Western Digital products - CVE-2022-23007
Published: September 27, 2022
Vulnerability identifier: #VU67661
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23007
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker on the local network can pass specially crafted input to the application to perform a denial of service (DoS) attack and pause the device upgrade.
Affected software
My Cloud Home
My Cloud Home Duo
SanDisk ibi
My Cloud Home Duo
SanDisk ibi
How to mitigate CVE-2022-23007
Install updates from vendor's website.
My Cloud Home - update to 8.10.0-117
My Cloud Home Duo - update to 8.10.0-117
SanDisk ibi - update to 8.10.0-117
My Cloud Home Duo - update to 8.10.0-117
SanDisk ibi - update to 8.10.0-117