CVE Feed

    Dashboard / CVE / CVE-2018-9075

    CVE-2018-9075

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

    Published:Sep 28, 2018
    Last Modified:Nov 21, 2024
    EPS:Sep 28, 2018
    EPSS Score:0.26448
    CVSS Score:8.1

    Affected Products

    Vendor
    Lenovo
    Product
    Iomega Ez Media \& Backup Center
    Vendor
    Lenovo
    Product
    Iomega Storcenter Ix2
    Vendor
    Lenovo
    Product
    Iomega Storcenter Ix2-dl
    Vendor
    Lenovo
    Product
    Iomega Storcenter Ix4-300d
    Vendor
    Lenovo
    Product
    Iomega Storcenter Px12-400r
    Vendor
    Lenovo
    Product
    Iomega Storcenter Px12-450r
    Vendor
    Lenovo
    Product
    Iomega Storcenter Px2-300d
    Vendor
    Lenovo
    Product
    Iomega Storcenter Px4-300d
    Vendor
    Lenovo
    Product
    Iomega Storcenter Px4-300r
    Vendor
    Lenovo
    Product
    Iomega Storcenter Px6-300d
    Vendor
    Lenovo
    Product
    Lenovo Ez Media \& Backup Center
    Vendor
    Lenovo
    Product
    Lenovo Ix2
    Vendor
    Lenovo
    Product
    Lenovo Ix4-300d
    Vendor
    Lenovo
    Product
    Lenovoemc Firmware
    Vendor
    Lenovo
    Product
    Lenovoemc Px12-400r
    Vendor
    Lenovo
    Product
    Lenovoemc Px12-450r
    Vendor
    Lenovo
    Product
    Lenovoemc Px2-300d
    Vendor
    Lenovo
    Product
    Lenovoemc Px4-300d
    Vendor
    Lenovo
    Product
    Lenovoemc Px4-300r
    Vendor
    Lenovo
    Product
    Lenovoemc Px4-400d
    Vendor
    Lenovo
    Product
    Lenovoemc Px4-400r
    Vendor
    Lenovo
    Product
    Lenovoemc Px6-300d

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High