MEDIUM · 4.1

CVE-2022-29839

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to us...

Vulnerability Description

Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.

CVSS Score

4.1

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WesterndigitalMy Cloud Os< 5.25.124
WesterndigitalMy Cloud-
WesterndigitalMy Cloud Dl2100-
WesterndigitalMy Cloud Dl4100-
WesterndigitalMy Cloud Ex2 Ultra-
WesterndigitalMy Cloud Ex2100-
WesterndigitalMy Cloud Ex4100-
WesterndigitalMy Cloud Mirror G2-
WesterndigitalMy Cloud Pr2100-
WesterndigitalMy Cloud Pr4100-
WesterndigitalWd Cloud-
LinuxLinux Kernel-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-29839?

CVE-2022-29839 is a vulnerability with a CVSS score of 4.1 (MEDIUM). Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to us...

How severe is CVE-2022-29839?

CVE-2022-29839 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-29839?

Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital My Cloud Os, Westerndigital My Cloud, Westerndigital My Cloud Dl2100, Westerndigital My Cloud Dl4100, Westerndigital My Cloud Ex2 Ultra.