Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
Published: 2018-09-28
Score: 8.1 High
EPSS: 25.5% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Lenovo Iomega Ez Media \& Backup Center Iomega Storcenter Ix2 Iomega Storcenter Ix2-dl Iomega Storcenter Ix4-300d Iomega Storcenter Px12-400r Iomega Storcenter Px12-450r Iomega Storcenter Px2-300d Iomega Storcenter Px4-300d Iomega Storcenter Px4-300r Iomega Storcenter Px6-300d Lenovo Ez Media \& Backup Center Lenovo Ix2 Lenovo Ix4-300d Lenovoemc Firmware Lenovoemc Px12-400r Lenovoemc Px12-450r Lenovoemc Px2-300d Lenovoemc Px4-300d Lenovoemc Px4-300r Lenovoemc Px4-400d Lenovoemc Px4-400r Lenovoemc Px6-300d
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-05T07:17:50.367Z

Reserved: 2018-03-27T00:00:00.000Z

Link: CVE-2018-9075

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-28T20:29:00.753

Modified: 2024-11-21T04:14:55.367

Link: CVE-2018-9075

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses