CVE-2022-22995
25.03.2022, 23:15
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Vendor | Product | Version |
---|---|---|
westerndigital | my_cloud_pr2100_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_pr4100_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_ex4100_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_ex2_ultra_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_mirror_gen_2_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_dl2100_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_dl4100_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_ex2100_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_firmware | 𝑥 < 5.19.117 |
westerndigital | wd_cloud_firmware | 𝑥 < 5.19.117 |
westerndigital | my_cloud_home_firmware | 𝑥 < 7.16-220 |
netatalk | netatalk | 𝑥 < 3.1.18 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References