Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.

Project Subscriptions

Vendors Products
Linux Kernel Subscribe
Westerndigital Subscribe
My Cloud Home Subscribe
My Cloud Home Duo Subscribe
My Cloud Home Duo Firmware Subscribe
My Cloud Home Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-28108 Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.
Fixes

Solution

My Cloud Home devices have been automatically updated to resolve this vulnerability


Workaround

No workaround given by the vendor.

History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03097}

epss

{'score': 0.01742}


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01757}

epss

{'score': 0.03097}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WDC PSIRT

Published:

Updated: 2024-08-03T03:28:42.830Z

Reserved: 2022-01-10T00:00:00

Link: CVE-2022-22997

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-07-12T21:15:09.393

Modified: 2024-11-21T06:47:46.327

Link: CVE-2022-22997

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses