ZeroHour

CVE-2022-22997

CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

Vendors
westerndigital
Products
my cloud home duo firmware, my cloud home firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.