CVE-2022-29844 is a critical vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware prior to version 5.26.119, allowing unauthenticated attackers to read and write arbitrary files. This remote, low-complexity attack can lead to full NAS compromise and remote code execution, as indicated by its CVSS score of 9.8. While there is no public exploit code or active exploitation reported, the vulnerability has garnered some community discussion. Organizations using affected devices should update their firmware immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.26.119CPE matchmatch criteria | cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:* | ||
< 5.26.119CPE matchmatch criteria | cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:* | ||
< 5.26.119CPE matchmatch criteria | cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:* | ||
< 5.26.119CPE matchmatch criteria | cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:* | ||
< 5.26.119CPE matchmatch criteria | cpe:2.3:o:westerndigital:my_cloud_mirror_g2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.