The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
Conclusion & alert: CVE-2022-22995 is rated High Risk (71.7/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.63%). Core evidence: EPSS rose +2.46% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.18% | 2.63% | +2.46% |
| 2 | 2025-11-21 | 1.65% | 0.18% | -1.47% |
| 3 | 2025-11-18 | — | 1.65% | — |
Full EPSS history (32 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 10.0 | 3.1 | CRITICAL |
|
3.9 | 6.0 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2022-22995: 1 source package rows (netatalk); 6 state rows across 6 repos (3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 6, open 0. | https://security.alpinelinux.org/vuln/CVE-2022-22995 |
debian
|
not yet assigned | CVE-2022-22995 not yet assigned priority: Debian including 1 source packages (netatalk), 4 status rows across 4 suites (bullseye, forky, sid, trixie): resolved 4. | https://security-tracker.debian.org/tracker/CVE-2022-22995 |
gentoo
|
high | CVE-2022-22995: 1 GLSA(s) (202311-02), 1 atom(s) (net-fs/netatalk); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2022-22995 |
suse
|
high | CVE-2022-22995 severity important: SUSE including 3 source package names (libatalk12-3.1.0-3.22.1, netatalk-3.1.0-3.22.1, netatalk-devel-3.1.0-3.22.1), 5 product×package rows across 2 product lines (SUSE Linux Enterprise Software Development Kit 12 SP5, SUSE Linux Enterprise Workstation Extension 12 SP5): Fixed 5. | https://www.suse.com/security/cve/CVE-2022-22995/ |
ubuntu
|
medium | CVE-2022-22995 medium priority: Ubuntu including 1 source packages (netatalk), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 7, released 3, ignored 2. | https://ubuntu.com/security/CVE-2022-22995 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| westerndigital | my_cloud_pr2100_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_pr4100_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_ex4100_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_ex2_ultra_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_mirror_gen_2_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_mirror_gen_2_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_dl2100_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_dl4100_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_ex2100_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:my_cloud_firmware:*:*:*:*:*:*:*:* |
| westerndigital | wd_cloud_firmware | < 5.19.117 | cpe:2.3:o:westerndigital:wd_cloud_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_home_firmware | < 7.16-220 | cpe:2.3:o:westerndigital:my_cloud_home_firmware:*:*:*:*:*:*:*:* |
| netatalk | netatalk | < 3.1.18 | cpe:2.3:a:netatalk:netatalk:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 37 | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
| fedoraproject | fedora | 38 | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
| fedoraproject | fedora | 39 | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |