Limited authentication bypass vulnerability on Western Digital My Cloud devices
Vulnerability Description
A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22990
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Reported By: Sam Thomas (@_s_n_t) of Pentest Ltd (@pentestltd) working with Trend Micro’s Zero Day Initiative
References
More from Western Digital
View All →Affected Vendor
Western Digital
View all reports →