CVE-2022-22995
EUVD-2022-2810625.03.2022, 23:15
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| westerndigital | my_cloud_pr2100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_pr4100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_ex4100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_ex2_ultra_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_mirror_gen_2_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_dl2100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_dl4100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_ex2100_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_firmware | 𝑥 < 5.19.117 |
| westerndigital | wd_cloud_firmware | 𝑥 < 5.19.117 |
| westerndigital | my_cloud_home_firmware | 𝑥 < 7.16-220 |
| netatalk | netatalk | 𝑥 < 3.1.18 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References