ZeroHour

CVE-2022-29843

CVSS 3.1
9.8 critical
EPSS
1%p66
Published
()
Modified
Description

A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.

Vendors
westerndigital
Products
my cloud pr2100 firmware, my cloud pr4100 firmware, my cloud ex4100 firmware, my cloud ex2 ultra firmware, my cloud mirror g2 firmware, my cloud dl2100 firmware, my cloud dl4100 firmware, my cloud ex2100 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.