CVE-2022-36331
Last modified
CVE-2022-36331 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102. . EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Westerndigital | My Cloud Pr2100 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Pr4100 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Ex4100 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Ex2 Ultra Firmware | < 5.25.132 |
| Westerndigital | My Cloud Mirror G2 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Dl2100 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Dl4100 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Ex2100 Firmware | < 5.25.132 |
| Westerndigital | My Cloud Home Firmware | < 8.13.1-102 |
| Westerndigital | My Cloud Home Duo Firmware | < 8.13.1-102 |
| Westerndigital | Sandisk Ibi Firmware | < 8.13.1-102 |
| Westerndigital | My Cloud Firmware | < 5.25.132 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36331?
How severe is CVE-2022-36331?
How do I fix CVE-2022-36331?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-36326An uncontrolled resource consumption vulnerability issue tha…4.9
- CVE-2022-36327Improper Limitation of a Pathname to a Restricted Directory …9.8
- CVE-2022-36328Improper Limitation of a Pathname to a Restricted Directory …4.9
- CVE-2022-36329An improper privilege management issue that could allow an a…7.5
- CVE-2022-3633A vulnerability classified as problematic has been found in …3.3
- CVE-2022-36330A buffer overflow vulnerability was discovered on firmware v…8.1
- CVE-2022-36336A link following vulnerability in the scanning function of T…7.8
- CVE-2022-36337An issue was discovered in Insyde InsydeH2O with kernel 5.0 …8.2
- CVE-2022-36338An issue was discovered in Insyde InsydeH2O with kernel 5.0 …8.2
- CVE-2022-36339Improper input validation in firmware for Intel(R) NUC 8 Com…7.8
- CVE-2022-3634The Contact Form 7 Database Addon WordPress plugin before 1.…9.8
- CVE-2022-36340Unauthenticated Optin Campaign Cache Deletion vulnerability …5.3
Are you affected by CVE-2022-36331?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
