High severity7.8NVD Advisory· Published Jan 28, 2022· Updated Jun 17, 2026
CVE-2022-22993
CVE-2022-22993
Description
A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: prior to 5.19.117
- Western Digital/My Cloudv5Range: My Cloud OS 5
Patches
Vulnerability mechanics
References
2- www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117nvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-22-348/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.