First published: Fri Sep 28 2018(Updated: )
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo StorCenter PX12-450R Firmware | ||
Lenovo PX12-400R | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo StorCenter PX4-300R | =4.1.402.34662 | |
Lenovo Storcenter PX4-300R Firmware | ||
Lenovo PX6-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX6-300D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX4-300D | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX2-300D | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo Storcenter IX4-300D Firmware | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter ix2-dl | ||
Lenovo StorCenter ix2-dl | =4.1.402.34662 | |
Lenovo StorCenter ix2-dl Firmware | ||
Lenovo EZ Media & Backup Center Firmware | =4.1.402.34662 | |
Lenovo Ez Media & Backup Center | ||
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo EMC px12-400r/450r | ||
Lenovo Storcenter PX12-400R Firmware | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo px4-400r | =4.1.402.34662 | |
Lenovo EMC px4-400r | ||
Lenovo Storcenter PX4-300R Firmware | =4.1.402.34662 | |
Lenovo StorCenter PX4-300R | ||
Lenovo StorCenter PX6-300D Firmware | =4.1.402.34662 | |
Lenovo EMC PX6-300D | ||
Lenovo PX4-400D | =4.1.402.34662 | |
Lenovo PX4-400D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px4-300d | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px2-300d | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC ix4-300d | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo ix2 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9081 has been classified as a medium severity vulnerability due to its potential for self-XSS exploitation in affected Iomega and Lenovo NAS devices.
To fix CVE-2018-9081, update the device firmware to a version later than 4.1.402.34662 that addresses the self-XSS vulnerability.
CVE-2018-9081 affects several Lenovo NAS devices running firmware version 4.1.402.34662 or earlier, including the Storcenter Px12, Px4, Px6, and Ix series.
CVE-2018-9081 is a self-cross-site scripting (self-XSS) vulnerability that allows an attacker to execute scripts in the context of a user's session.
CVE-2018-9081 is primarily an internal threat as it involves self-XSS, which requires user interaction to exploit.