CVE-2022-22995: Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in Netatalk
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22995?
CVE-2022-22995 is a vulnerability that allows arbitrary writing of files in the default configuration of SMB and AFP.
What software is affected by CVE-2022-22995?
Westerndigital My Cloud Pr2100 Firmware, Westerndigital My Cloud Pr4100 Firmware, Westerndigital My Cloud Ex4100 Firmware, Westerndigital My Cloud Ex2 Ultra Firmware, Westerndigital My Cloud Mirror Gen 2 Firmware, Westerndigital My Cloud Dl2100 Firmware, Westerndigital My Cloud Dl4100 Firmware, Westerndigital My Cloud Ex2100 Firmware, Westerndigital My Cloud Firmware, Westerndigital Wd Cloud Firmware, and Westerndigital My Cloud Home Firmware are affected by CVE-2022-22995.
How severe is CVE-2022-22995?
CVE-2022-22995 has a severity rating of 9.8 (Critical).
How can I fix CVE-2022-22995?
To fix CVE-2022-22995, it is recommended to update the firmware of the affected devices to a version higher than 5.19.117 for My Cloud Pr2100, My Cloud Pr4100, My Cloud Ex4100, My Cloud Ex2 Ultra, My Cloud Mirror Gen 2, My Cloud Dl2100, My Cloud Dl4100, My Cloud Ex2100, My Cloud Firmware, and Wd Cloud Firmware. For My Cloud Home, update to version 7.16-220 or higher.
Where can I find more information about CVE-2022-22995?
More information about CVE-2022-22995 can be found at the following references: [Link 1](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T5CZZLFOTUP3QYHGHSDUNENGSLPJ6KGO/), [Link 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XO34FWOIJI6V6PH2XY52WNBBARVWPJG2/), [Link 3](https://www.westerndigital.com/support/product-security/wdc-22005-netatalk-security-vulnerabilities).