Vulnerabilities > Westerndigital > MY Cloud Home DUO Firmware > 7.16.0.220

DATE CVE VULNERABILITY TITLE RISK
2022-09-27 CVE-2022-23006 Out-of-bounds Write vulnerability in Westerndigital products
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that could allow an attacker accessing the system locally to read information from /etc/version file.
local
high complexity
westerndigital CWE-787
6.7
2022-07-12 CVE-2022-22997 OS Command Injection vulnerability in Westerndigital MY Cloud Home DUO Firmware and MY Cloud Home Firmware
Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.
network
low complexity
westerndigital CWE-78
7.5
2022-07-12 CVE-2022-22998 Insufficiently Protected Credentials vulnerability in Westerndigital MY Cloud Home DUO Firmware and MY Cloud Home Firmware
Implemented protections on AWS credentials that were not properly protected.
network
low complexity
westerndigital CWE-522
5.0