Path traversal in Western Digital products - CVE-2022-36328
Published: February 28, 2023 / Updated: June 9, 2023
Vulnerability identifier: #VU72621
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-36328
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the restsdk binary. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
My Cloud Home
My Cloud Home Duo
SanDisk ibi
My Cloud Home Duo
SanDisk ibi
How to mitigate CVE-2022-36328
Install update from vendor's website.
My Cloud Home - update to 9.4.0-191
My Cloud Home Duo - update to 9.4.0-191
SanDisk ibi - update to 9.4.0-191
My Cloud Home Duo - update to 9.4.0-191
SanDisk ibi - update to 9.4.0-191