Vulnerabilities > Westerndigital > Sandisk IBI Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-12 CVE-2022-36331 Authentication Bypass by Spoofing vulnerability in Westerndigital products
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
network
low complexity
westerndigital CWE-290
7.5
2023-05-10 CVE-2022-36329 Unspecified vulnerability in Westerndigital products
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
network
low complexity
westerndigital
7.5
2023-05-10 CVE-2022-36330 Classic Buffer Overflow vulnerability in Westerndigital products
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.
network
high complexity
westerndigital CWE-120
8.1
2022-12-01 CVE-2022-29837 Path Traversal vulnerability in Westerndigital products
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files.
local
low complexity
westerndigital CWE-22
7.8