ZeroHour

CVE-2022-22995

CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

Vendors
westerndigitalnetatalkfedoraproject
Products
my cloud pr2100 firmware, my cloud pr4100 firmware, my cloud ex4100 firmware, my cloud ex2 ultra firmware, my cloud mirror gen 2 firmware, my cloud dl2100 firmware, my cloud dl4100 firmware, my cloud ex2100 firmware, my cloud firmware, wd cloud firmware, my cloud home firmware, netatalk
Weakness
CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.