CVE-2022-36331
Summary
| CVE | CVE-2022-36331 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-12 18:15:00 UTC |
| Updated | 2023-06-21 13:05:00 UTC |
| Description | Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102. |
Risk And Classification
Problem Types: CWE-290
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| WDC-22020 - Western Digital My Cloud OS 5, My Cloud Home and SanDisk ibi Firmware Update | Western Digital | MISC | www.westerndigital.com | Vendor Advisory |
| https/www.westerndigital.com/support/product-security/wdc-22020-my-... | MISC | https | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.