CVE-2022-22995

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
WDC PSIRTCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
VendorProductVersion
westerndigitalmy_cloud_pr2100_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_pr4100_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_ex4100_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_ex2_ultra_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_mirror_gen_2_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_dl2100_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_dl4100_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_ex2100_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_firmware
𝑥
< 5.19.117
westerndigitalwd_cloud_firmware
𝑥
< 5.19.117
westerndigitalmy_cloud_home_firmware
𝑥
< 7.16-220
netatalknetatalk
𝑥
< 3.1.18
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
netatalk
bullseye (security)
vulnerable
bullseye
no-dsa
sid
4.0.3~ds-2
fixed
trixie
4.0.3~ds-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
netatalk
noble
not-affected
mantic
ignored
lunar
ignored
jammy
Fixed 3.1.12~ds-9ubuntu0.22.04.3+esm1
released
focal
Fixed 3.1.12~ds-4ubuntu0.20.04.3+esm1
released
bionic
not-affected
xenial
not-affected
trusty
not-affected