CVE-2022-22988 - CVE House
Back to Database
Status published High CVE-2022-22988

Insecure file and directory permissions on EdgeRover

Vulnerability Description

File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only be exploited once an attacker has already found a way to get authenticated access to the device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22988

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Western Digital

View all reports →

Affected Software

EdgeRover
Vulnerable Versions:
EdgeRover Mac Desktop App, EdgeRover Windows Desktop App

Timeline

Official Publish: January 13th, 2022
Last Modified: August 3rd, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.