Path traversal in Western Digital products - CVE-2022-29836
Published: November 14, 2022
Vulnerability identifier: #VU69273
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29836
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and initiate the installation of custom packages.
Affected software
My Cloud Home
My Cloud Home Duo
SanDisk ibi
My Cloud Home Duo
SanDisk ibi
How to mitigate CVE-2022-29836
Install update from vendor's website.
My Cloud Home - update to 8.11.0-113
My Cloud Home Duo - update to 8.11.0-113
SanDisk ibi - update to 8.11.0-113
My Cloud Home Duo - update to 8.11.0-113
SanDisk ibi - update to 8.11.0-113