Unrated severityNVD Advisory· Published Jan 28, 2022· Updated Aug 3, 2024
Limited Server-Side Request Forgery vulnerability on Western Digital My Cloud devices.
CVE-2022-22993
Description
A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: OS5 (firmware < 5.19.117)
- Western Digital/My Cloudv5Range: My Cloud OS 5
Patches
Vulnerability mechanics
References
2- www.westerndigital.com/support/product-security/wdc-22002-my-cloud-os5-firmware-5-19-117mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-22-348/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.