CVE-2022-22995
25.03.2022, 23:15
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
| Vendor | Product | Version |
|---|---|---|
| westerndigital | my_cloud_pr2100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_pr4100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_ex4100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_ex2_ultra_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_mirror_gen_2_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_dl2100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_dl4100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_ex2100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_firmware | 𝑥 < 5.19.117 |
| westerndigital | wd_cloud_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_home_firmware | 𝑥 < 7.16-220 |
| netatalk | netatalk | 𝑥 < 3.1.18 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References