CVE-2022-22997 MEDIUM

CVE-2022-22997: Command Injection Vulnerability on My Cloud Home

Vendor Western Digital
Product My Cloud Home
Weakness CWE-78
Published July 12, 2022
Last update August 3, 2024

CVSS base score

6.8/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

Key dates

02Disclosure timeline

July 12, 2022 CVE published
August 3, 2024 Record updated