{"id": "CVE-2022-36331", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 3.9}, {"type": "Secondary", "source": "psirt@wdc.com", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 10.0, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 6.0, "exploitabilityScore": 3.9}]}, "published": "2023-06-12T18:15:09.747", "references": [{"url": "https://https://www.westerndigital.com/support/product-security/wdc-22020-my-cloud-os-5-my-cloud-home-ibi-firmware-update", "tags": ["Broken Link"], "source": "psirt@wdc.com"}, {"url": "https://www.westerndigital.com/support/product-security/wdc-22020-my-cloud-os-5-my-cloud-home-ibi-firmware-update", "tags": ["Vendor Advisory"], "source": "nvd@nist.gov"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-290"}]}, {"type": "Secondary", "source": "psirt@wdc.com", "description": [{"lang": "en", "value": "CWE-290"}]}], "descriptions": [{"lang": "en", "value": "Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data.\nThis issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.\n\n"}], "lastModified": "2023-06-21T13:05:23.150", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "BF58260B-2131-402C-A9DA-67B188136DE1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B66F84E3-4B1F-4359-9CB9-C4DA88012CBC", "versionEndExcluding": "5.25.132"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CB0C2FD9-4792-4DA2-9698-E53109A499EC"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41816E5B-6A6F-47AF-8EB3-065CEAE2F905", "versionEndExcluding": "5.25.132"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B95A4FC-8694-42CA-8F12-0EB42A596B2C", "versionEndExcluding": "5.25.132"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B78030F0-6655-4604-9D16-2FA1F3FD52FF"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CF78188-7B7B-4672-8553-34616F21E740", "versionEndExcluding": "5.25.132"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5A581EBA-A1F2-4ABC-8183-29973A46FA43"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_mirror_g2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6BDE1153-A1A1-495C-BADA-409721BBC3F3", "versionEndExcluding": "5.25.132"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_mirror_g2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6DE090BC-C847-4DF7-9C5F-52A300845558"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9AE31BDF-EF2A-4A9F-AFEA-EDA4125598D4", "versionEndExcluding": "5.25.132"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9E783EBC-7608-4527-B1AD-9B4E7A7A108C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F3034F4A-239C-4E38-9BD6-217361A7C519"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C9AC1B82-BDCC-42F6-AFCF-BDC036EDBA23", "versionEndExcluding": "5.25.132"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "ABBBDC1E-2320-4767-B669-1BB2FFB1E1C4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71600FC4-BF21-4BA4-BC67-DC9EA43920DC", "versionEndExcluding": "5.25.132"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_home:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2BE2FBAB-5BA0-4F09-A76E-4A6869668810"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_home_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1E0D7EFC-04BD-467F-89A8-50A5E6541F75", "versionEndExcluding": "8.13.1-102"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud_home_duo:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "124BBC79-65A2-465C-B784-D21E57E96F63"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_home_duo_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "19584F79-F6AD-4348-A420-D6D7634C678B", "versionEndExcluding": "8.13.1-102"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:sandisk_ibi:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "296ADA43-16BA-4444-B472-DB945FB917B2"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:sandisk_ibi_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "470DB475-1C91-43F7-A0E1-0B38FEC6AAA3", "versionEndExcluding": "8.13.1-102"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3A9EE86B-05EE-4F2E-A912-624DDCF9C41B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:westerndigital:my_cloud_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB0CF5DA-8CEC-4E0C-864F-D18B79F92E0F", "versionEndExcluding": "5.25.132"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "psirt@wdc.com"}