Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-22993

Опубликовано: 28 янв. 2022
Источник: nvd
CVSS3: 7.8
CVSS3: 8.8
CVSS2: 8.3
EPSS Низкий

Описание

A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:westerndigital:my_cloud_os:*:*:*:*:*:*:*:*
Версия до 5.19.117 (исключая)

Одно из

cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:-:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:wd_cloud:-:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00057
Низкий

7.8 High

CVSS3

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-918
CWE-918

Связанные уязвимости

CVSS3: 8.8
github
около 4 лет назад

A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.

EPSS

Процентиль: 18%
0.00057
Низкий

7.8 High

CVSS3

8.8 High

CVSS3

8.3 High

CVSS2

Дефекты

CWE-918
CWE-918