CVE-2022-29835: WD Discovery's Use of Weak Hashing Algorithm for Code Signing
WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this weakness to create forged certificate signatures due to the use of a hashing algorithm that is not collision-free. This could thereby impact the confidentiality of user content. This issue affects: Western Digital WD Discovery WD Discovery Desktop App versions prior to 4.4.396 on Mac; WD Discovery Desktop App versions prior to 4.4.396 on Windows.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-29835?
CVE-2022-29835 refers to a vulnerability in the WD Discovery software, where the executable files were signed with an unsafe SHA-1 hashing algorithm.
How does CVE-2022-29835 impact user content?
CVE-2022-29835 can impact the confidentiality of user content due to the possibility of forged certificate signatures.
What is the severity of CVE-2022-29835?
CVE-2022-29835 has a severity rating of 5.3, which is considered medium.
Which versions of the WD Discovery software are affected by CVE-2022-29835?
WD Discovery software versions up to 4.4.396 for both macOS and Windows are affected by CVE-2022-29835.
How can I fix CVE-2022-29835?
To fix CVE-2022-29835, users should update their WD Discovery software to a version beyond 4.4.396.