Show plain JSON{"id": "CVE-2022-29835", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "psirt@wdc.com", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 5.3, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "REQUIRED", "attackComplexity": "HIGH", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 1.6}]}, "published": "2022-09-19T20:15:12.370", "references": [{"url": "https://www.westerndigital.com/support/product-security/wdc-22014-wd-discovery-desktop-app-version-4-4-396", "tags": ["Vendor Advisory"], "source": "psirt@wdc.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-326"}]}, {"type": "Secondary", "source": "psirt@wdc.com", "description": [{"lang": "en", "value": "CWE-328"}]}], "descriptions": [{"lang": "en", "value": "WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality of user content. This issue affects: Western Digital WD Discovery WD Discovery Desktop App versions prior to 4.4.396 on Mac; WD Discovery Desktop App versions prior to 4.4.396 on Windows."}, {"lang": "es", "value": "Los archivos ejecutables del software WD Discovery estaban firmados con un algoritmo hash SHA-1 no seguro. Un atacante podr\u00eda usar esta debilidad para crear firmas de certificados falsificadas debido al uso de un algoritmo de hashing que no est\u00e1 libre de colisiones. Esto podr\u00eda afectar a la confidencialidad del contenido del usuario. Este problema afecta a: Western Digital WD Discovery WD Discovery Desktop App versiones anteriores a 4.4.396 en Mac; WD Discovery Desktop App versiones anteriores a 4.4.396 en Windows"}], "lastModified": "2023-07-21T16:55:33.250", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:westerndigital:wd_discovery:*:*:*:*:*:macos:*:*", "vulnerable": true, "matchCriteriaId": "32CCB6CE-EF49-4E1C-A7A6-289E6B50B757", "versionEndExcluding": "4.4.396"}, {"criteria": "cpe:2.3:a:westerndigital:wd_discovery:*:*:*:*:*:windows:*:*", "vulnerable": true, "matchCriteriaId": "D64710E0-57D7-4668-870D-7C21959A45B0", "versionEndExcluding": "4.4.396"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@wdc.com"}