Path traversal in Western Digital products - CVE-2022-36327

 

Path traversal in Western Digital products - CVE-2022-36327

Published: February 28, 2023


Vulnerability identifier: #VU72620
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36327
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote attacker can send a specially crafted HTTP request and write arbitrary files on the system, leading to arbitrary code execution.


Affected software

My Cloud Home
My Cloud Home Duo
SanDisk ibi

How to mitigate CVE-2022-36327

Install update from vendor's website.

My Cloud Home - update to 9.4.0-191
My Cloud Home Duo - update to 9.4.0-191
SanDisk ibi - update to 9.4.0-191

External References

Related Security Bulletins