CVE-2018-9079: Iomega and LenovoEMC NAS Web UI Vulnerabilities
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9079?
CVE-2018-9079 has a medium severity rating due to its potential impact on the Document Object Model (DOM) and the ability to execute arbitrary JavaScript in affected devices.
How do I fix CVE-2018-9079?
To fix CVE-2018-9079, update the device firmware to a version later than 4.1.402.34662.
Which devices are affected by CVE-2018-9079?
CVE-2018-9079 affects several Iomega, Lenovo, and LenovoEMC NAS devices running firmware version 4.1.402.34662 or earlier.
Can CVE-2018-9079 allow remote execution of scripts?
Yes, CVE-2018-9079 can allow adversaries to inject HTML script tags and execute arbitrary JavaScript remotely.
What are the consequences of not addressing CVE-2018-9079?
Failing to address CVE-2018-9079 could lead to unauthorized access, data manipulation, or further exploitation of the vulnerable NAS devices.