First published: Fri Sep 28 2018(Updated: )
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo StorCenter PX12-450R Firmware | ||
Lenovo PX12-400R | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo StorCenter PX4-300R | =4.1.402.34662 | |
Lenovo Storcenter PX4-300R Firmware | ||
Lenovo PX6-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX6-300D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX4-300D | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX2-300D | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo Storcenter IX4-300D Firmware | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter ix2-dl | ||
Lenovo StorCenter ix2-dl | =4.1.402.34662 | |
Lenovo StorCenter ix2-dl Firmware | ||
Lenovo EZ Media & Backup Center Firmware | =4.1.402.34662 | |
Lenovo Ez Media & Backup Center | ||
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo EMC px12-400r/450r | ||
Lenovo Storcenter PX12-400R Firmware | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo px4-400r | =4.1.402.34662 | |
Lenovo EMC px4-400r | ||
Lenovo Storcenter PX4-300R Firmware | =4.1.402.34662 | |
Lenovo StorCenter PX4-300R | ||
Lenovo StorCenter PX6-300D Firmware | =4.1.402.34662 | |
Lenovo EMC PX6-300D | ||
Lenovo PX4-400D | =4.1.402.34662 | |
Lenovo PX4-400D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px4-300d | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px2-300d | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC ix4-300d | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo ix2 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9079 has a medium severity rating due to its potential impact on the Document Object Model (DOM) and the ability to execute arbitrary JavaScript in affected devices.
To fix CVE-2018-9079, update the device firmware to a version later than 4.1.402.34662.
CVE-2018-9079 affects several Iomega, Lenovo, and LenovoEMC NAS devices running firmware version 4.1.402.34662 or earlier.
Yes, CVE-2018-9079 can allow adversaries to inject HTML script tags and execute arbitrary JavaScript remotely.
Failing to address CVE-2018-9079 could lead to unauthorized access, data manipulation, or further exploitation of the vulnerable NAS devices.