CVE-2019-6178: Medium severity lenovo px12-350r firmware vulnerability
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6178?
CVE-2019-6178 is classified as a medium severity information leakage vulnerability in Lenovo and Iomega NAS products.
How do I fix CVE-2019-6178?
To mitigate CVE-2019-6178, disable Personal Cloud features in the affected NAS devices.
What devices are affected by CVE-2019-6178?
CVE-2019-6178 affects Lenovo PX12-350R, IX12-300R, Home Media Network Hard Drive, Storecenter Ix2-200, Ix4-200d, and Ix4-200rl with specific firmware versions.
Can CVE-2019-6178 lead to data theft?
CVE-2019-6178 does not allow read, write, or delete access to the file systems, limiting the risk of data theft.
Is there a patch available for CVE-2019-6178?
There is no specific patch mentioned for CVE-2019-6178; users should follow mitigation steps.