SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2022-36331

CRITICAL · CVSS 10 EPSS 0.59%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-12 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 10.0. Exploitation may require the attacker to be authenticated.

CVE
CVE-2022-36331
Severity
CRITICAL
CVSS
10
EPSS
0.59%

Original NVD Description

Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.

Related CVEs

Other vulnerabilities affecting the same vendor(s)