CVE-2018-9074
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
Published:Sep 28, 2018
Last Modified:Nov 21, 2024
EPS:Sep 28, 2018
EPSS Score:0.00343
CVSS Score:6.5
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Iomega Ez Media \& Backup Center
Lenovo
Iomega Ez Media \& Backup Center
Vendor
Lenovo
Product
Iomega Storcenter Ix2
Lenovo
Iomega Storcenter Ix2
Vendor
Lenovo
Product
Iomega Storcenter Ix2-dl
Lenovo
Iomega Storcenter Ix2-dl
Vendor
Lenovo
Product
Iomega Storcenter Ix4-300d
Lenovo
Iomega Storcenter Ix4-300d
Vendor
Lenovo
Product
Iomega Storcenter Px12-400r
Lenovo
Iomega Storcenter Px12-400r
Vendor
Lenovo
Product
Iomega Storcenter Px12-450r
Lenovo
Iomega Storcenter Px12-450r
Vendor
Lenovo
Product
Iomega Storcenter Px2-300d
Lenovo
Iomega Storcenter Px2-300d
Vendor
Lenovo
Product
Iomega Storcenter Px4-300d
Lenovo
Iomega Storcenter Px4-300d
Vendor
Lenovo
Product
Iomega Storcenter Px4-300r
Lenovo
Iomega Storcenter Px4-300r
Vendor
Lenovo
Product
Iomega Storcenter Px6-300d
Lenovo
Iomega Storcenter Px6-300d
Vendor
Lenovo
Product
Lenovo Ez Media \& Backup Center
Lenovo
Lenovo Ez Media \& Backup Center
Vendor
Lenovo
Product
Lenovo Ix2
Lenovo
Lenovo Ix2
Vendor
Lenovo
Product
Lenovo Ix4-300d
Lenovo
Lenovo Ix4-300d
Vendor
Lenovo
Product
Lenovoemc Firmware
Lenovo
Lenovoemc Firmware
Vendor
Lenovo
Product
Lenovoemc Px12-400r
Lenovo
Lenovoemc Px12-400r
Vendor
Lenovo
Product
Lenovoemc Px12-450r
Lenovo
Lenovoemc Px12-450r
Vendor
Lenovo
Product
Lenovoemc Px2-300d
Lenovo
Lenovoemc Px2-300d
Vendor
Lenovo
Product
Lenovoemc Px4-300d
Lenovo
Lenovoemc Px4-300d
Vendor
Lenovo
Product
Lenovoemc Px4-300r
Lenovo
Lenovoemc Px4-300r
Vendor
Lenovo
Product
Lenovoemc Px4-400d
Lenovo
Lenovoemc Px4-400d
Vendor
Lenovo
Product
Lenovoemc Px4-400r
Lenovo
Lenovoemc Px4-400r
Vendor
Lenovo
Product
Lenovoemc Px6-300d
Lenovo
Lenovoemc Px6-300d
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
