CVE-2018-9074: Iomega and LenovoEMC NAS Web UI Vulnerabilities
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9074?
CVE-2018-9074 is classified as a high severity vulnerability due to its potential to allow unauthorized file uploads as the root user.
How do I fix CVE-2018-9074?
To remediate CVE-2018-9074, upgrade your affected Lenovo or Iomega NAS device firmware to version 4.1.402.34663 or later.
Which devices are affected by CVE-2018-9074?
CVE-2018-9074 affects Lenovo and Iomega NAS devices running firmware versions up to and including 4.1.402.34662.
What consequences can occur if CVE-2018-9074 is exploited?
Exploitation of CVE-2018-9074 may allow attackers to upload arbitrary files, potentially leading to unauthorized access and compromise of the device.
How can I check if my device is vulnerable to CVE-2018-9074?
You can check if your device is vulnerable to CVE-2018-9074 by verifying the installed firmware version against the known vulnerable versions.