First published: Fri Sep 28 2018(Updated: )
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo LenovoEMC firmware | <=4.1.402.34662 | |
Lenovo Iomega ez media \& backup center | ||
Lenovo Iomega storcenter ix2 | ||
Lenovo Iomega storcenter ix2-dl | ||
Lenovo EMC ix4-300d | ||
Lenovo EMC px12-400r IVX | ||
Lenovo EMC px12-450r | ||
Lenovo Iomega storcenter px2-300d | ||
Lenovo Iomega storcenter px4-300d | ||
Lenovo Iomega storcenter px4-300r | ||
Lenovo Iomega storcenter px6-300d | ||
Lenovo Lenovo ez media \& backup center | ||
Lenovo EMC ix2/ix2-dl | ||
Lenovo EMC ix4-300d | ||
Lenovo LenovoEMC px12-400r | ||
Lenovo LenovoEMC px12-450r | ||
Lenovo EMC px2-300d | ||
Lenovo EMC px4-300d | ||
Lenovo EMC px4-300r | ||
Lenovo EMC px4-400d | ||
Lenovo EMC px4-400r | ||
Lenovo EMC px6-300d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9074 is classified as a high severity vulnerability due to its potential to allow unauthorized file uploads as the root user.
To remediate CVE-2018-9074, upgrade your affected Lenovo or Iomega NAS device firmware to version 4.1.402.34663 or later.
CVE-2018-9074 affects Lenovo and Iomega NAS devices running firmware versions up to and including 4.1.402.34662.
Exploitation of CVE-2018-9074 may allow attackers to upload arbitrary files, potentially leading to unauthorized access and compromise of the device.
You can check if your device is vulnerable to CVE-2018-9074 by verifying the installed firmware version against the known vulnerable versions.