MEDIUM · 4.4

CVE-2022-36329

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk i...

Vulnerability Description

An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.

CVSS Score

4.4

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
WesterndigitalMy Cloud Home Firmware< 9.4.0-191
WesterndigitalMy Cloud Home-
WesterndigitalMy Cloud Home Duo Firmware< 9.4.0-191
WesterndigitalMy Cloud Home Duo-
WesterndigitalSandisk Ibi Firmware< 9.4.0-191
WesterndigitalSandisk Ibi-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-36329?

CVE-2022-36329 is a vulnerability with a CVSS score of 4.4 (MEDIUM). An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk i...

How severe is CVE-2022-36329?

CVE-2022-36329 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-36329?

Check the references section above for vendor advisories and patch information. Affected products include: Westerndigital My Cloud Home Firmware, Westerndigital My Cloud Home, Westerndigital My Cloud Home Duo Firmware, Westerndigital My Cloud Home Duo, Westerndigital Sandisk Ibi Firmware.