← volver
CVE-2022-29839

Remote Backups Application Discloses Stored Credentials

CVSS 4.1 MEDIUMEPSS 0.1%CWE-522
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.1EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
09 dic 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western Digital My Cloud My Cloud versions prior to 5.25.124 on Linux.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Productos afectados
Western Digital · My Cloud

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →