CVE-2018-9076: Iomega and LenovoEMC NAS Web UI Vulnerabilities
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value c and iomega parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9076?
CVE-2018-9076 is classified as a high severity vulnerability due to its potential for command injection leading to arbitrary command execution.
How do I fix CVE-2018-9076?
To mitigate CVE-2018-9076, upgrade your affected Lenovo or Iomega NAS devices to firmware version 4.1.402.34663 or later.
Which devices are affected by CVE-2018-9076?
CVE-2018-9076 affects Iomega and Lenovo NAS devices running firmware versions 4.1.402.34662 and earlier.
What kind of vulnerability is CVE-2018-9076?
CVE-2018-9076 is a command injection vulnerability that allows attackers to execute arbitrary commands through a crafted share name.
Is CVE-2018-9076 publicly known?
Yes, CVE-2018-9076 is publicly disclosed and documented within the Common Vulnerabilities and Exposures database.