CVE-2022-22994: (Pwn2Own) Western Digital My Cloud Pro Series PR4100 ConnectivityService Insufficient Verification of Data Authenticity Remote Code Execution Vulnerability
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Western Digital MyCloud PR4100. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ConnectivityService service. The issue results from the lack of proper authentication of data received via HTTP. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22994.
What is the severity of CVE-2022-22994?
The severity of CVE-2022-22994 is critical with a CVSS score of 9.8.
How can network-adjacent attackers exploit CVE-2022-22994?
Network-adjacent attackers can exploit CVE-2022-22994 to execute arbitrary code on affected installations of Western Digital MyCloud PR4100 without authentication.
What is the affected software by CVE-2022-22994?
The affected software by CVE-2022-22994 is Western Digital My Cloud OS version up to 5.19.117.
How can I fix CVE-2022-22994?
To fix CVE-2022-22994, update the firmware of Western Digital MyCloud PR4100 to version 5.19.117 or later.