Western Digital My Cloud Home Duo vulnerabilities

3 known vulnerabilities affecting western_digital/my_cloud_home_duo.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-22817MEDIUMCVSS 5.5fixed in 9.5.1-1042024-02-05
CVE-2023-22817 [MEDIUM] CWE-918 CVE-2023-22817: Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local networ Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that refer to loopback. This issue affe
nvd
CVE-2023-22819MEDIUMCVSS 4.9fixed in 9.5.1-1042024-02-05
CVE-2023-22819 [MEDIUM] CWE-770 CVE-2023-22819: An uncontrolled resource consumption vulnerability issue that could arise by sending crafted request An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue r
nvd
CVE-2022-23006MEDIUMCVSS 6.7≥ 8.10.0-117, < 8.10.0-1172022-09-27
CVE-2022-23006 [MEDIUM] CWE-121 CVE-2022-23006: A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Hom A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file. This vulnerability can only be exploited by chaining it with another issue. If an attacker is able to carry out a remote code
nvd