CVE-2022-36330 - CVE House
Back to Database
Status published Low CVE-2022-36330

Buffer Overflow Vulnerability in Western Digital My Cloud Home and ibi devices

Vulnerability Description

A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-36330

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Western Digital

View all reports →

Affected Software

My Cloud Home and My Cloud Home Duo, ibi
Vulnerable Versions:
0

Timeline

Official Publish: May 9th, 2023
Last Modified: January 28th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N

Weaknesses (CWE)