First published: Fri Sep 28 2018(Updated: )
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo StorCenter PX12-450R Firmware | ||
Lenovo PX12-400R | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo StorCenter PX4-300R | =4.1.402.34662 | |
Lenovo Storcenter PX4-300R Firmware | ||
Lenovo PX6-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX6-300D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX4-300D | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX2-300D | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo Storcenter IX4-300D Firmware | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter ix2-dl | ||
Lenovo StorCenter ix2-dl | =4.1.402.34662 | |
Lenovo StorCenter ix2-dl Firmware | ||
Lenovo EZ Media & Backup Center Firmware | =4.1.402.34662 | |
Lenovo Ez Media & Backup Center | ||
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo EMC px12-400r/450r | ||
Lenovo Storcenter PX12-400R Firmware | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo px4-400r | =4.1.402.34662 | |
Lenovo EMC px4-400r | ||
Lenovo Storcenter PX4-300R Firmware | =4.1.402.34662 | |
Lenovo StorCenter PX4-300R | ||
Lenovo StorCenter PX6-300D Firmware | =4.1.402.34662 | |
Lenovo EMC PX6-300D | ||
Lenovo PX4-400D | =4.1.402.34662 | |
Lenovo PX4-400D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px4-300d | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px2-300d | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC ix4-300d | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo ix2 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9078 has been identified as a medium severity vulnerability that allows unauthorized file uploads due to improper handling in the Content Explorer application.
To fix CVE-2018-9078, update the affected Iomega and Lenovo NAS devices to the latest firmware version beyond 4.1.402.34662.
Devices affected by CVE-2018-9078 include Lenovo Storcenter models Px12-450r, Px12-400r, Px4-300r, Px6-300d, and others running firmware version 4.1.402.34662.
The risks associated with CVE-2018-9078 include potential unauthorized access and manipulation of files on the vulnerable NAS devices.
As of the latest information, there have been no reported active exploits for CVE-2018-9078, but it remains a vulnerability that should be addressed.