CVE-2022-29843: Western Digital My Cloud OS 5 devices Command Injection Vulnerability
Published Jan 25, 2023
·Updated
A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 allows an attacker to execute code in the context of the root user.
Affected Software
16 affected components
WesternDigital My Cloud Pr2100 Firmware<5.26.119
WesternDigital My Cloud Pr2100
WesternDigital My Cloud Pr4100 Firmware<5.26.119
WesternDigital My Cloud Pr4100
WesternDigital My Cloud Ex4100 Firmware<5.26.119
WesternDigital My Cloud Ex4100
WesternDigital My Cloud Ex2 Ultra Firmware<5.26.119
WesternDigital My Cloud Ex2 Ultra
WesternDigital My Cloud Mirror G2 Firmware<5.26.119
WesternDigital My Cloud Mirror G2
WesternDigital My Cloud Dl2100 Firmware<5.26.119
WesternDigital My Cloud Dl2100
WesternDigital My Cloud Dl4100 Firmware<5.26.119
WesternDigital My Cloud Dl4100
WesternDigital My Cloud Ex2100 Firmware<5.26.119
WesternDigital My Cloud Ex2100
Remediation
Information
Western Digital recommends that users promptly update their devices to the latest firmware by clicking on the firmware update notification.
Event History
Jan 25, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-29843?
The severity of CVE-2022-29843 is critical with a CVSS score of 9.8.
2
How does CVE-2022-29843 affect Western Digital My Cloud OS 5 devices?
CVE-2022-29843 affects Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119.
3
What is the impact of CVE-2022-29843?
CVE-2022-29843 allows an attacker to execute code in the context of the root user.
4
How can I fix CVE-2022-29843?
To fix CVE-2022-29843, update the firmware of your Western Digital My Cloud OS 5 device to version 5.26.119 or above.
5
Where can I find more information about CVE-2022-29843?
You can find more information about CVE-2022-29843 on the Western Digital support website.