CVE-2022-29840: Server Side Request Forgery Vulnerability in Western Digital My Cloud Devices
Server-Side Request Forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL to point back to the loopback adapter was addressed in Western Digital My Cloud OS 5 devices. This could allow the URL to exploit other vulnerabilities on the local server.This issue affects My Cloud OS 5 devices before 5.26.202.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-29840?
CVE-2022-29840 is a Server-Side Request Forgery (SSRF) vulnerability found in Western Digital My Cloud OS 5 devices.
How does CVE-2022-29840 work?
CVE-2022-29840 allows a rogue server on the local network to modify its URL to point back to the loopback adapter, which can be used to exploit other vulnerabilities on the local server.
Which versions of Western Digital My Cloud OS are affected by CVE-2022-29840?
CVE-2022-29840 affects versions up to 5.02.104 and 5.26.202 of Western Digital My Cloud OS.
What is the severity of CVE-2022-29840?
CVE-2022-29840 has a severity rating of medium (5.5).
How can I fix CVE-2022-29840?
To fix CVE-2022-29840, you should update your Western Digital My Cloud OS to version 5.26.202 or later.