#VU60709 Server-Side Request Forgery (SSRF) in Western Digital products - CVE-2022-22993
Published: February 18, 2022
My Cloud PR2100
My Cloud PR4100
My Cloud EX4100
My Cloud EX2 Ultra
My Cloud Mirror Gen 2
My Cloud DL2100
My Cloud DL4100
My Cloud EX2100
WD My Cloud
My Cloud
My Cloud OS 5
Western Digital
Description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the cgi_api endpoint. A remote user on the local network can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.