Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
Published: 2018-09-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-20677 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
History

No history.

Subscriptions

Lenovo Iomega Ez Media \& Backup Center Iomega Storcenter Ix2 Iomega Storcenter Ix2-dl Iomega Storcenter Ix4-300d Iomega Storcenter Px12-400r Iomega Storcenter Px12-450r Iomega Storcenter Px2-300d Iomega Storcenter Px4-300d Iomega Storcenter Px4-300r Iomega Storcenter Px6-300d Lenovo Ez Media \& Backup Center Lenovo Ix2 Lenovo Ix4-300d Lenovoemc Firmware Lenovoemc Px12-400r Lenovoemc Px12-450r Lenovoemc Px2-300d Lenovoemc Px4-300d Lenovoemc Px4-300r Lenovoemc Px4-400d Lenovoemc Px4-400r Lenovoemc Px6-300d
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-05T07:17:50.355Z

Reserved: 2018-03-27T00:00:00.000Z

Link: CVE-2018-9074

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-28T20:29:00.643

Modified: 2024-11-21T04:14:55.240

Link: CVE-2018-9074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses