MEDIUM · 6.7

CVE-2022-29844

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full ...

Vulnerability Description

A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full NAS compromise and would give remote execution capabilities to the attacker.

CVSS Score

6.7

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
WesterndigitalMy Cloud Pr2100 Firmware< 5.26.119
WesterndigitalMy Cloud Pr2100-
WesterndigitalMy Cloud Pr4100 Firmware< 5.26.119
WesterndigitalMy Cloud Pr4100-
WesterndigitalMy Cloud Ex4100 Firmware< 5.26.119
WesterndigitalMy Cloud Ex4100-
WesterndigitalMy Cloud Ex2 Ultra Firmware< 5.26.119
WesterndigitalMy Cloud Ex2 Ultra-
WesterndigitalMy Cloud Mirror G2 Firmware< 5.26.119
WesterndigitalMy Cloud Mirror G2-
WesterndigitalMy Cloud Dl2100 Firmware< 5.26.119
WesterndigitalMy Cloud Dl2100-
WesterndigitalMy Cloud Dl4100 Firmware< 5.26.119
WesterndigitalMy Cloud Dl4100-
WesterndigitalMy Cloud Ex2100 Firmware< 5.26.119
WesterndigitalMy Cloud Ex2100-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-29844?

CVE-2022-29844 is a vulnerability with a CVSS score of 6.7 (MEDIUM). A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to read and write arbitrary files. This could lead to a full ...

How severe is CVE-2022-29844?

CVE-2022-29844 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-29844?

Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital My Cloud Pr2100 Firmware, Westerndigital My Cloud Pr2100, Westerndigital My Cloud Pr4100 Firmware, Westerndigital My Cloud Pr4100, Westerndigital My Cloud Ex4100 Firmware.