threat
engine
.sh
Back
·
··:··
Home
/
Product
/
westerndigital sandisk ibi firmware
Product
westerndigital sandisk ibi firmware
11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-22819
< 9.5.1-104
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a la
4.9
MEDIUM
CVE-2023-22817
< 9.5.1-104
Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using anot
5.5
MEDIUM
CVE-2022-36331
< 8.13.1-102
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack tha
10.0
CRITICAL
CVE-2022-36328
< 9.4.0-191
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to creat
5.8
MEDIUM
CVE-2022-36327
< 9.4.0-191
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write
5.8
MEDIUM
CVE-2022-36326
< 9.4.0-191
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a la
4.4
MEDIUM
CVE-2022-36329
< 9.4.0-191
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discov
4.4
MEDIUM
CVE-2022-36330
< 9.4.0-191
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code ex
1.9
LOW
CVE-2022-29837
< 8.12.0-178
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow
4.7
MEDIUM
CVE-2022-29836
< 8.11.0-113
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP API on Wes
1.9
LOW
CVE-2022-23006
< 8.10.0-117
A stack-based buffer overflow vulnerability was found on Western Digital My Cloud Home, My Cloud Home Duo, and SanDisk ibi that co
1.8
LOW
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin