CVE-2022-22993
EUVD-2022-2810428.01.2022, 20:15
A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| westerndigital | my_cloud_os | 𝑥 < 5.19.117 |
𝑥
= Vulnerable software versions
References