CVE-2022-36330: Buffer Overflow Vulnerability in Western Digital My Cloud Home and ibi devices
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability.
This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the CVE ID?
The CVE ID for this vulnerability is CVE-2022-36330.
What is the severity of CVE-2022-36330?
The severity of CVE-2022-36330 is high (8.1).
Which products are affected by CVE-2022-36330?
CVE-2022-36330 affects Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.
How can an attacker exploit CVE-2022-36330?
An attacker can exploit CVE-2022-36330 by exploiting another vulnerability to raise their privileges and then perform an unauthenticated remote code execution.
Is there a fix available for CVE-2022-36330?
Yes, Western Digital has released a firmware version 9.4.0-191 to address the vulnerability. It is recommended to update to this version.