CVE-2022-29837 MEDIUM

CVE-2022-29837: Path traversal Vulnerability in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi Devices

Vendor Western Digital
Product My Cloud Home
Weakness CWE-22 · Path traversal
Published December 1, 2022
Last update April 24, 2025

CVSS base score

4.7/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

What the vulnerability does

01Description

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

Key dates

02Disclosure timeline

December 1, 2022 CVE published
April 24, 2025 Record updated