Rogue Server Could Modify URL to Exploit Vulnerabilities on Local Server
CVE-2023-22817

5.5MEDIUM

Key Information:

Vendor
CVE Published:
5 February 2024

What is CVE-2023-22817?

A server-side request forgery vulnerability exists in Western Digital's My Cloud and SanDisk ibi product lines, enabling attackers on the local network to exploit DNS address manipulation. This vulnerability can allow malicious servers to redirect requests to the loopback adapter, potentially uncovering internal vulnerabilities within the server. Affected devices include My Cloud OS 5 before version 5.27.161, My Cloud Home, My Cloud Home Duo, and SanDisk ibi before version 9.5.1-104. The issue has been mitigated by addressing misconfigured DNS address resolutions that point to the loopback interface.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ibi Linux 0 < 9.5.1-104

My Cloud Home & Duo Linux 0 < 9.5.1-104

My Cloud OS 5 Linux 0 < 5.27.161

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sam Thomas (@_s_n_t) of Pentest Ltd (@pentestltd) working with Trend Micro’s Zero Day Initiative
.