Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
Published: 2018-09-28
Score: 8.1 High
EPSS: 1.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-20680 For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
History

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.01439}

epss

{'score': 0.0187}


Subscriptions

Lenovo Iomega Ez Media \& Backup Center Iomega Storcenter Ix2 Iomega Storcenter Ix2-dl Iomega Storcenter Ix4-300d Iomega Storcenter Px12-400r Iomega Storcenter Px12-450r Iomega Storcenter Px2-300d Iomega Storcenter Px4-300d Iomega Storcenter Px4-300r Iomega Storcenter Px6-300d Lenovo Ez Media \& Backup Center Lenovo Ix2 Lenovo Ix4-300d Lenovoemc Firmware Lenovoemc Px12-400r Lenovoemc Px12-450r Lenovoemc Px2-300d Lenovoemc Px4-300d Lenovoemc Px4-300r Lenovoemc Px4-400d Lenovoemc Px4-400r Lenovoemc Px6-300d
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-08-05T07:17:50.598Z

Reserved: 2018-03-27T00:00:00.000Z

Link: CVE-2018-9077

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-09-28T20:29:00.970

Modified: 2024-11-21T04:14:55.630

Link: CVE-2018-9077

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses