PT-2023-2419 · Western Digital · Western Digital My Cloud

CVE-2022-29844

·

Publicado

2023-01-10

·

Atualizado

2023-04-24

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Western Digital My Cloud OS versions prior to 5.26.119
Description The issue is related to the FTP service, where an incorrect restriction of a directory path name with limited access allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise, giving the attacker remote execution capabilities. The vulnerability is associated with the FTP service of Western Digital My Cloud OS, where exploitation can allow a remote attacker to gain full access to the device and execute arbitrary code.
Recommendations For versions prior to 5.26.119, update the firmware to version 5.26.119 or later to resolve the issue. As a temporary workaround, consider disabling the FTP service until a patch is available. Restrict access to the FTP server to minimize the risk of exploitation.

Correção

Relative Path Traversal

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02204
CVE-2022-29844
ZDI-23-112

Produtos afetados

Western Digital My Cloud