CVE-2022-22989

Critical
|9.8
Exploit Available

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows attackers on the same network to take control of the My Cloud OS 5 device by exploiting a flaw in its FTP service, even without needing to log in. It’s critical to address this issue because it can lead to unauthorized access and potential data loss or manipulation.

Technical Description

My Cloud OS 5 was vulnerable to a pre-authenticated stack overflow vulnerability on the FTP service that could be exploited by unauthenticated attackers on the network. Addressed the vulnerability by adding defenses against stack overflow issues.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$13,000($5K-$15K)
Vendor Response
Grade FPatched in 1502 days

Quick Information

Published

Jan 13, 2022

about 4 years ago

Last Modified

Feb 24, 2026

about 1 month ago

Vendor

westerndigital

Product

my cloud os