CVE-2022-23006 - CVE House
Back to Database
Status published Low CVE-2022-23006

Buffer Overflow Vulnerability in Western Digital My Cloud Home Products and SanDisk ibi

Vulnerability Description

A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code execution attack, they can gain access to the vulnerable file, due to the presence of insecure functions in code. User interaction is required for exploitation. Exploiting the vulnerability could result in exposure of information, ability to modify files, memory access errors, or system crashes.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23006

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Western Digital

View all reports →

Affected Software

My Cloud Home, My Cloud Home Duo, ibi
Vulnerable Versions:
8.10.0-117

Timeline

Official Publish: September 27th, 2022
Last Modified: May 21st, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)