Users of Western Digital’s EdgeRover app for Windows and Mac are advised to download an updated version to avoid a security flaw that would allow an attacker to gain unauthorized access to directories and files.
The bug, which received the CVE identification number CVE-2022-22988, has a Common Vulnerability Scoring System (CVSS) gravity rating of 9.1, which makes it a critical vulnerability. It has now been addressed, but with a change to the way EdgeRover handles file and directory permissions.
According to Western Digital, the error meant that EdgeRover was subject to a directory-traversal vulnerability, which allowed an attacker to perform a local privilege escalation and override file system sandboxing. If successfully exploited, this could lead to the release of sensitive information or even a potential denial-of-service attack, the company said.
Western Digital has posted a notification on its support page informing users of both Windows and Mac versions of the EdgeRover desktop app that they need to make sure they are running at least release version 1.5.1-594 for the Fix for to have this topic.
The EdgeRover app is designed to give users a single view of their content that can be distributed across different storage devices and cloud storage services. EdgeRover creates a visible and visible catalog of all content, and also provides tools for managing supported Western Digital and SanDisk storage devices.
In particular, EdgeRover is capable of changing vital settings on supported Western Digital and SanDisk devices, including the ability to set passwords, delete content, and rename devices, allowing an attacker plenty of leeway to cause abuse.
This is not the first security fix for EdgeRover to come this year. In January, the company advised users to download an updated release to address some vulnerabilities, but in that case these were due to an open source tool, the FFmpeg Multimedia Framework, used by EdgeRover.
With that vulnerability, an exploit could have caused a denial of service or allowed an attacker to execute code through the avenue to present malformed files or streams for processing. This vulnerability also had a CVSS severity rating of 9.1. ®

Add Comment