Vulnerability Name:

CVE-2022-23006 (CCN-237667)

Assigned:2022-01-10
Published:2022-01-10
Updated:2022-10-03
Summary:A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code execution attack, they can gain access to the vulnerable file, due to the presence of insecure functions in code. User interaction is required for exploitation. Exploiting the vulnerability could result in exposure of information, ability to modify files, memory access errors, or system crashes.
CVSS v3 Severity:6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
5.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
1.8 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N)
1.6 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): High
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:0.8 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:M/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Multiple_Instances
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2022-23006

Source: XF
Type: UNKNOWN
westerndigital-cve202223006-bo(237667)

Source: CCN
Type: Western Digital Web site
My Cloud Home, My Cloud Home Duo, and SanDisk

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/h:western_digital:my_cloud:-:*:*:*:*:*:*:*
  • OR cpe:/h:westerndigital:my_cloud_home_duo:-:*:*:*:*:*:*:*
  • OR cpe:/h:westerndigital:sandisk_ibi:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    western_digital my cloud -
    westerndigital my cloud home duo -
    westerndigital sandisk ibi -