CVE-2023-22817: Server-side Request Forgery vulnerability in Western Digital My Cloud, My Cloud Home and SanDisk ibi products
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that refer to loopback. This issue affects My Cloud OS 5 devices before 5.27.161, My Cloud Home, My Cloud Home Duo and SanDisk ibi devices before 9.5.1-104.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22817?
CVE-2023-22817 is classified as a server-side request forgery (SSRF) vulnerability.
How do I fix CVE-2023-22817?
To fix CVE-2023-22817, update your affected Western Digital My Cloud firmware to a version greater than 5.27.161 or 9.5.1-104.
Which products are affected by CVE-2023-22817?
CVE-2023-22817 affects several Western Digital My Cloud devices, including PR2100, PR4100, EX4100, and others with outdated firmware.
Can CVE-2023-22817 allow remote exploitation?
CVE-2023-22817 could potentially allow a rogue server to exploit other vulnerabilities hosted on the same local server.
What types of attacks can CVE-2023-22817 facilitate?
CVE-2023-22817 can facilitate attacks that modify request URLs, enabling further exploitation of vulnerabilities on the local server.