CVE-2022-22997: Command Injection Vulnerability on My Cloud Home
Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-22997?
CVE-2022-22997 is a remote code execution vulnerability in My Cloud Home devices.
How does CVE-2022-22997 work?
CVE-2022-22997 allows an attacker to execute unsigned code on My Cloud Home devices by exploiting a command injection vulnerability and accessing the AWS S3 bucket.
How severe is CVE-2022-22997?
CVE-2022-22997 has a severity rating of 9.8, which is considered critical.
Which software versions are affected by CVE-2022-22997?
My Cloud Home devices with firmware versions up to 8.5.1-102 are affected by CVE-2022-22997.
How can I fix CVE-2022-22997?
To fix CVE-2022-22997, update your My Cloud Home device firmware to version 8.7.0-107 or later. Check the provided link for more information.