Back to Database
Status published
Critical
CVE-2022-22989
Pre-authenticated stack overflow vulnerability on FTP Service
Vulnerability Description
My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22989
Credits & Attribution
No credits recorded in the NVD database.
References
More from Western Digital
View All →CVE-2025-30248
DLL hijacking in the WD Discovery Installer in Western Digital...
High
8.9
CVE-2025-30247
An OS command injection vulnerability in user interface in Western...
Critical
9.3
CVE-2024-22170
Unchecked buffer in Dynamic DNS client
Critical
9.2
CVE-2024-22169
Misconfiguration in node.js causing a code execution in WD Discovery
High
7.1
CVE-2024-22168
Cross-Site Scripting (XSS) vulnerability on Western Digital My Cloud and SanDisk ibi Web Apps
Medium
5.9
Affected Vendor
Western Digital
View all reports →Affected Software
My Cloud
Vulnerable Versions:
My Cloud OS 5
Timeline
Official Publish:
January 13th, 2022
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H