MEDIUM · 6.2

CVE-2022-29843

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the conte...

Vulnerability Description

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.

CVSS Score

6.2

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
WesterndigitalMy Cloud Pr2100 Firmware< 5.26.119
WesterndigitalMy Cloud Pr2100-
WesterndigitalMy Cloud Pr4100 Firmware< 5.26.119
WesterndigitalMy Cloud Pr4100-
WesterndigitalMy Cloud Ex4100 Firmware< 5.26.119
WesterndigitalMy Cloud Ex4100-
WesterndigitalMy Cloud Ex2 Ultra Firmware< 5.26.119
WesterndigitalMy Cloud Ex2 Ultra-
WesterndigitalMy Cloud Mirror G2 Firmware< 5.26.119
WesterndigitalMy Cloud Mirror G2-
WesterndigitalMy Cloud Dl2100 Firmware< 5.26.119
WesterndigitalMy Cloud Dl2100-
WesterndigitalMy Cloud Dl4100 Firmware< 5.26.119
WesterndigitalMy Cloud Dl4100-
WesterndigitalMy Cloud Ex2100 Firmware< 5.26.119
WesterndigitalMy Cloud Ex2100-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-29843?

CVE-2022-29843 is a vulnerability with a CVSS score of 6.2 (MEDIUM). A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the conte...

How severe is CVE-2022-29843?

CVE-2022-29843 has been rated MEDIUM with a CVSS base score of 6.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-29843?

Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital My Cloud Pr2100 Firmware, Westerndigital My Cloud Pr2100, Westerndigital My Cloud Pr4100 Firmware, Westerndigital My Cloud Pr4100, Westerndigital My Cloud Ex4100 Firmware.