The Western Digital My Cloud Web App [https://os5.mycloud.com/] uses a weak SSLContext when attempting to configure port forwarding rules. This was enabled to maintain compatibility with old or outdated home routers. By using an "SSL" context instead of "TLS" or specifying stronger validation, deprecated or insecure protocols are permitted. As a result, a local user with no privileges can exploit this vulnerability and jeopardize the integrity, confidentiality and authenticity of information transmitted. The scope of impact cannot extend to other components and no user input is required to exploit this vulnerability.
Conclusion & alert: CVE-2022-23000 is rated Moderate Risk (40.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.13%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-08 | 0.05% | 0.13% | +0.08% |
| 2 | 2025-07-27 | 0.05% | 0.05% | -0.00% |
| 3 | 2025-05-21 | — | 0.05% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
2.5 | 4.7 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| westerndigital | my_cloud_pr2100_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_pr2100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_pr4100_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_ex4100_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_ex4100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_ex2_ultra_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_ex2_ultra_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_mirror_g2_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_mirror_g2_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_dl2100_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_dl2100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_dl4100_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_dl4100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_ex2100_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_ex2100_firmware:*:*:*:*:*:*:*:* |
| westerndigital | my_cloud_firmware | < 5.23.114 | cpe:2.3:o:westerndigital:my_cloud_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.westerndigital.com/support/product-security/wdc-22011-my-cloud-firmware-version-5-23-114 | Vendor Advisory |