CVE-2018-9078
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.
Published:Sep 28, 2018
Last Modified:Nov 21, 2024
EPS:Sep 28, 2018
EPSS Score:0.0047
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Lenovo
Product
Ez Media \& Backup Center
Lenovo
Ez Media \& Backup Center
Vendor
Lenovo
Product
Ez Media \& Backup Center Firmware
Lenovo
Ez Media \& Backup Center Firmware
Vendor
Lenovo
Product
Ix2
Lenovo
Ix2
Vendor
Lenovo
Product
Ix2 Firmware
Lenovo
Ix2 Firmware
Vendor
Lenovo
Product
Ix4-300d
Lenovo
Ix4-300d
Vendor
Lenovo
Product
Ix4-300d Firmware
Lenovo
Ix4-300d Firmware
Vendor
Lenovo
Product
Px12-400r
Lenovo
Px12-400r
Vendor
Lenovo
Product
Px12-400r Firmware
Lenovo
Px12-400r Firmware
Vendor
Lenovo
Product
Px12-450r
Lenovo
Px12-450r
Vendor
Lenovo
Product
Px12-450r Firmware
Lenovo
Px12-450r Firmware
Vendor
Lenovo
Product
Px2-300d
Lenovo
Px2-300d
Vendor
Lenovo
Product
Px2-300d Firmware
Lenovo
Px2-300d Firmware
Vendor
Lenovo
Product
Px4-300d
Lenovo
Px4-300d
Vendor
Lenovo
Product
Px4-300d Firmware
Lenovo
Px4-300d Firmware
Vendor
Lenovo
Product
Px4-300r
Lenovo
Px4-300r
Vendor
Lenovo
Product
Px4-300r Firmware
Lenovo
Px4-300r Firmware
Vendor
Lenovo
Product
Px4-400d
Lenovo
Px4-400d
Vendor
Lenovo
Product
Px4-400d Firmware
Lenovo
Px4-400d Firmware
Vendor
Lenovo
Product
Px4-400r
Lenovo
Px4-400r
Vendor
Lenovo
Product
Px4-400r Firmware
Lenovo
Px4-400r Firmware
Vendor
Lenovo
Product
Px6-300d
Lenovo
Px6-300d
Vendor
Lenovo
Product
Px6-300d Firmware
Lenovo
Px6-300d Firmware
Vendor
Lenovo
Product
Storcenter Ix2
Lenovo
Storcenter Ix2
Vendor
Lenovo
Product
Storcenter Ix2-dl
Lenovo
Storcenter Ix2-dl
Vendor
Lenovo
Product
Storcenter Ix2-dl Firmware
Lenovo
Storcenter Ix2-dl Firmware
Vendor
Lenovo
Product
Storcenter Ix2 Firmware
Lenovo
Storcenter Ix2 Firmware
Vendor
Lenovo
Product
Storcenter Ix4-300d
Lenovo
Storcenter Ix4-300d
Vendor
Lenovo
Product
Storcenter Ix4-300d Firmware
Lenovo
Storcenter Ix4-300d Firmware
Vendor
Lenovo
Product
Storcenter Px12-400r
Lenovo
Storcenter Px12-400r
Vendor
Lenovo
Product
Storcenter Px12-400r Firmware
Lenovo
Storcenter Px12-400r Firmware
Vendor
Lenovo
Product
Storcenter Px12-450r
Lenovo
Storcenter Px12-450r
Vendor
Lenovo
Product
Storcenter Px12-450r Firmware
Lenovo
Storcenter Px12-450r Firmware
Vendor
Lenovo
Product
Storcenter Px2-300d
Lenovo
Storcenter Px2-300d
Vendor
Lenovo
Product
Storcenter Px2-300d Firmware
Lenovo
Storcenter Px2-300d Firmware
Vendor
Lenovo
Product
Storcenter Px4-300d
Lenovo
Storcenter Px4-300d
Vendor
Lenovo
Product
Storcenter Px4-300d Firmware
Lenovo
Storcenter Px4-300d Firmware
Vendor
Lenovo
Product
Storcenter Px4-300r
Lenovo
Storcenter Px4-300r
Vendor
Lenovo
Product
Storcenter Px4-300r Firmware
Lenovo
Storcenter Px4-300r Firmware
Vendor
Lenovo
Product
Storcenter Px6-300d
Lenovo
Storcenter Px6-300d
Vendor
Lenovo
Product
Storcenter Px6-300d Firmware
Lenovo
Storcenter Px6-300d Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
