{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2022-29837","assignerOrgId":"cb3b742e-5145-4748-b44b-5ffd45bf3b6a","assignerShortName":"WDC PSIRT","dateUpdated":"2025-04-24T20:12:31.109Z","dateReserved":"2022-04-27T00:00:00.000Z","datePublished":"2022-12-01T00:00:00.000Z"},"containers":{"cna":{"title":"Path traversal Vulnerability in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi Devices","providerMetadata":{"orgId":"cb3b742e-5145-4748-b44b-5ffd45bf3b6a","shortName":"WDC PSIRT","dateUpdated":"2022-12-01T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution."}],"affected":[{"vendor":"Western Digital","product":"My Cloud Home","versions":[{"version":"My Cloud Home ","status":"affected","lessThan":"8.12.0-178","versionType":"custom"},{"version":"My Cloud Home Duo","status":"affected","lessThan":"8.12.0-178","versionType":"custom"}],"platforms":["Linux"]},{"vendor":"SanDisk","product":"ibi","versions":[{"version":"ibi","status":"affected","lessThan":"8.12.0-178","versionType":"custom"}],"platforms":["Linux"]}],"references":[{"url":"https://www.westerndigital.com/support/product-security/wdc-22018-western-digital-my-cloud-home-my-cloud-home-duo-and-sandisk-ibi-firmware-version-8-12-0-178"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM"}}],"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","cweId":"CWE-22"}]}],"x_generator":{"engine":"Vulnogram 0.0.9"},"source":{"discovery":"EXTERNAL"},"solutions":[{"lang":"en","value":"The user's My Cloud Home, My Cloud Home Duo and ibi devices will be automatically updated to reflect the latest firmware version."}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-03T06:33:42.797Z"},"title":"CVE Program Container","references":[{"url":"https://www.westerndigital.com/support/product-security/wdc-22018-western-digital-my-cloud-home-my-cloud-home-duo-and-sandisk-ibi-firmware-version-8-12-0-178","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-04-24T20:12:21.544434Z","id":"CVE-2022-29837","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-04-24T20:12:31.109Z"}}]}}