- Mar 13, 2022
- 599
Western Digital has blocked access to its cloud services for devices running firmware versions impacted by a known and critical security vulnerability.
The move, which began on June 15, comes one month after the company released firmware updates for its My Cloud product line to address multiple security defects, including a critical path traversal bug that leads to remote code execution (RCE).
The issue is tracked as CVE-2022-36327 and carries CVSS severity score of 9.8/10. According to a NIST advisory, the flaw “could allow an attacker to write files to locations with certain critical filesystem types.”
The flaw impacts Western Digital’s My Cloud Home, My Cloud Home Duo, SanDisk ibi, and My Cloud OS 5 devices and requires the attackers to first trigger an authentication bypass vulnerability.
Western Digital Blocks Unpatched Devices From Cloud Services
Western Digital is blocking access to its cloud services for devices running firmware versions impacted by a critical security vulnerability.
www.securityweek.com