First published: Mon Aug 19 2019(Updated: )
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Px12-350r Firmware | =4.0.24.34808 | |
Lenovo Px12-350r Firmware | ||
Lenovo Ix12-300r | =4.0.24.34808 | |
Lenovo Ix12-300r Firmware | ||
Lenovo Home Media Network Hard Drive Firmware | =3.2.16.30221 | |
Lenovo Home Media Network Hard Drive | ||
Lenovo Storcenter Ix2-200 Firmware | =3.2.16.30221 | |
Lenovo Storecenter Ix2-200 Firmware | ||
Lenovo Storcenter Ix4-200d Firmware | =3.2.16.30221 | |
Lenovo Storcenter Ix4-200d | ||
Lenovo Storcenter Ix2-200 Firmware | =2.1.50.30227 | |
Lenovo Storecenter Ix2-200 Firmware | ||
Lenovo Storcenter Ix4-200d Firmware | =2.1.50.30227 | |
Lenovo Storcenter Ix4-200d | ||
Lenovo Storecenter Ix4-200rl | =2.1.50.30227 | |
Lenovo Storcenter Ix4-200rl |
To protect your device against this vulnerability, disable Personal Cloud. If Personal Cloud is enabled, avoid using sensitive share names and only use the device on trusted networks.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6178 is classified as a medium severity information leakage vulnerability in Lenovo and Iomega NAS products.
To mitigate CVE-2019-6178, disable Personal Cloud features in the affected NAS devices.
CVE-2019-6178 affects Lenovo PX12-350R, IX12-300R, Home Media Network Hard Drive, Storecenter Ix2-200, Ix4-200d, and Ix4-200rl with specific firmware versions.
CVE-2019-6178 does not allow read, write, or delete access to the file systems, limiting the risk of data theft.
There is no specific patch mentioned for CVE-2019-6178; users should follow mitigation steps.