Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-36330— Buffer Overflow Vulnerability in Western Digital My Cloud Home and ibi devices

CVSS 1.9 · Low EPSS 0.48% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-36330

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Buffer Overflow Vulnerability in Western Digital My Cloud Home and ibi devices
Source: NVD (National Vulnerability Database)
Vulnerability Description
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability. This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191. 
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Western Digital My Cloud Home 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Western Digital My Cloud Home是美国西部数据(Western Digital)公司的一款易于使用的个人云存储设备。可直接插入 Wi-Fi 路由器,从而保护数字生活。 Western Digital My Cloud Home 9.4.0-191之前版本和My Cloud Home Duo 9.4.0-191之前版本存在安全漏洞。攻击者利用该漏洞可以升级权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Western DigitalMy Cloud Home and My Cloud Home Duo 0 ~ 9.4.0-191 -
SanDiskibi 0 ~ 9.4.0-191 -

II. Public POCs for CVE-2022-36330

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-36330

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2022-36330

No comments yet


Leave a comment