Vulnerability Name:

CVE-2022-22999 (CCN-232206)

Assigned:2022-07-25
Published:2022-07-25
Updated:2022-08-01
Summary:Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may be possible to gain control over the authenticated session, steal data, modify settings, or redirect the user to malicious websites. The scope of impact can extend to other components.
CVSS v3 Severity:4.8 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
7.8 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2022-22999

Source: XF
Type: UNKNOWN
wdc-cve202222999-xss(232206)

Source: CCN
Type: WDC Tracking Number: WDC-22011
My Cloud Firmware Version 5.23.114

Source: MISC
Type: Vendor Advisory
https://www.westerndigital.com/support/product-security/wdc-22011-my-cloud-firmware-version-5-23-114

Vulnerable Configuration:Configuration 1:
  • cpe:/o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:westerndigital:my_cloud_mirror_g2_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_mirror_g2:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:* (Version < 5.23.114)
  • AND
  • cpe:/h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:western_digital:my_cloud:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    westerndigital my cloud pr2100 firmware *
    westerndigital my cloud pr2100 -
    westerndigital my cloud pr4100 firmware *
    westerndigital my cloud pr4100 -
    westerndigital my cloud ex4100 firmware *
    westerndigital my cloud ex4100 -
    westerndigital my cloud ex2 ultra firmware *
    westerndigital my cloud ex2 ultra -
    westerndigital my cloud mirror g2 firmware *
    westerndigital my cloud mirror g2 -
    westerndigital my cloud dl2100 firmware *
    westerndigital my cloud dl2100 -
    westerndigital my cloud dl4100 firmware *
    westerndigital my cloud dl4100 -
    westerndigital my cloud ex2100 firmware *
    westerndigital my cloud ex2100 -
    western_digital my cloud -