CVE-2022-22992

A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:westerndigital:my_cloud_os:*:*:*:*:*:*:*:*
OR cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:-:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:wd_cloud:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-01-28 20:15

Updated : 2023-07-11 20:21


NVD link : CVE-2022-22992

Mitre link : CVE-2022-22992

CVE.ORG link : CVE-2022-22992


JSON object : View

Products Affected

westerndigital

  • my_cloud_ex2_ultra
  • my_cloud_pr4100
  • my_cloud_dl2100
  • wd_cloud
  • my_cloud_mirror_gen_2
  • my_cloud_ex2100
  • my_cloud_dl4100
  • my_cloud
  • my_cloud_pr2100
  • my_cloud_ex4100
  • my_cloud_os
CWE
CWE-116

Improper Encoding or Escaping of Output