CVE-2022-22991: (Pwn2Own) Western Digital MyCloud PR4100 ConnectivityService Command Injection Remote Code Execution Vulnerability
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity using HTTP.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConnectivityService service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
— ZDI
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22991?
CVE-2022-22991 is a vulnerability that allows network-adjacent attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100.
Is authentication required to exploit CVE-2022-22991?
No, authentication is not required to exploit this vulnerability.
What is the severity of CVE-2022-22991?
The severity of CVE-2022-22991 is high with a CVSS score of 8.8.
Which software versions of Western Digital MyCloud PR4100 are affected by CVE-2022-22991?
Western Digital MyCloud PR4100 with My Cloud OS version up to exclusive 5.19.117 is affected by this vulnerability.
How can I fix CVE-2022-22991?
To fix CVE-2022-22991, update your Western Digital MyCloud PR4100 to the latest firmware version.