CVE-2022-36331: Impersonation attack causing an Authentication Bypass on Western Digital devices
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-36331?
CVE-2022-36331 is a vulnerability that affects Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.
How severe is CVE-2022-36331?
CVE-2022-36331 has a severity rating of 7.5 (out of 10), indicating it is critical.
Which devices are affected by CVE-2022-36331?
CVE-2022-36331 affects Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.
How can an attacker exploit CVE-2022-36331?
CVE-2022-36331 can be exploited by an unauthenticated attacker to gain access to user data.
How can I fix CVE-2022-36331?
To fix CVE-2022-36331, update your affected devices to My Cloud OS 5 devices version 5.25.132 or later.