The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
|
History
21 Nov 2024, 06:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://lists.debian.org/debian-lts-announce/2024/01/msg00000.html - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/55ROUJI22SHZX5EM23QAILZHI67EZQKW/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T5CZZLFOTUP3QYHGHSDUNENGSLPJ6KGO/ - Mailing List | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XO34FWOIJI6V6PH2XY52WNBBARVWPJG2/ - Mailing List | |
References | () https://security.gentoo.org/glsa/202311-02 - Issue Tracking, Third Party Advisory | |
References | () https://www.westerndigital.com/support/product-security/wdc-22005-netatalk-security-vulnerabilities - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 10.0 |
04 Jan 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
28 Dec 2023, 15:19
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CPE | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:* |
31 Mar 2022, 01:12
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
CWE | CWE-59 | |
References | (MISC) https://www.westerndigital.com/support/product-security/wdc-22005-netatalk-security-vulnerabilities - Vendor Advisory | |
CPE | cpe:2.3:h:westerndigital:my_cloud_ex4100:-:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:wd_cloud:-:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_dl4100:-:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_mirror_gen_2:-:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_dl2100:-:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:wd_cloud_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_home_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_pr2100:-:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_mirror_gen_2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_ex2100:-:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_home:-:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud_ex2_ultra:-:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:westerndigital:my_cloud:-:*:*:*:*:*:*:* |
25 Mar 2022, 23:37
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-25 23:15
Updated : 2024-11-21 06:47
NVD link : CVE-2022-22995
Mitre link : CVE-2022-22995
CVE.ORG link : CVE-2022-22995
JSON object : View
Products Affected
westerndigital
- my_cloud_ex2100
- my_cloud_firmware
- my_cloud_mirror_gen_2_firmware
- my_cloud_dl2100
- my_cloud_pr2100
- my_cloud_ex2_ultra
- my_cloud_pr2100_firmware
- my_cloud_dl4100_firmware
- my_cloud_pr4100_firmware
- my_cloud
- my_cloud_mirror_gen_2
- wd_cloud
- my_cloud_pr4100
- my_cloud_home_firmware
- my_cloud_ex2_ultra_firmware
- wd_cloud_firmware
- my_cloud_ex2100_firmware
- my_cloud_ex4100
- my_cloud_dl2100_firmware
- my_cloud_ex4100_firmware
- my_cloud_dl4100
- my_cloud_home
fedoraproject
- fedora
netatalk
- netatalk
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')