CVE-2022-29837Path Traversal in IBI

CWE-22Path Traversal2 documents2 sources
Severity
7.8HIGHNVD
EPSS
0.1%
top 74.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 1

Description

A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5western_digital/my_cloud_homeMy Cloud Home 8.12.0-178+1
CVEListV5sandisk/ibiibi8.12.0-178

🔴Vulnerability Details

1
GHSA
GHSA-xj3g-h9f3-349x: A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to init2022-12-01