Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity Low
Privileges Required None
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.00543.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Ez Media \& Backup Center
Subscribe
Ez Media \& Backup Center Firmware
Subscribe
Ix2
Subscribe
Ix2 Firmware
Subscribe
Ix4-300d
Subscribe
Ix4-300d Firmware
Subscribe
Px12-400r
Subscribe
Px12-400r Firmware
Subscribe
Px12-450r
Subscribe
Px12-450r Firmware
Subscribe
Px2-300d
Subscribe
Px2-300d Firmware
Subscribe
Px4-300d
Subscribe
Px4-300d Firmware
Subscribe
Px4-300r
Subscribe
Px4-300r Firmware
Subscribe
Px4-400d
Subscribe
Px4-400d Firmware
Subscribe
Px4-400r
Subscribe
Px4-400r Firmware
Subscribe
Px6-300d
Subscribe
Px6-300d Firmware
Subscribe
Storcenter Ix2
Subscribe
Storcenter Ix2-dl
Subscribe
Storcenter Ix2-dl Firmware
Subscribe
Storcenter Ix2 Firmware
Subscribe
Storcenter Ix4-300d
Subscribe
Storcenter Ix4-300d Firmware
Subscribe
Storcenter Px12-400r
Subscribe
Storcenter Px12-400r Firmware
Subscribe
Storcenter Px12-450r
Subscribe
Storcenter Px12-450r Firmware
Subscribe
Storcenter Px2-300d
Subscribe
Storcenter Px2-300d Firmware
Subscribe
Storcenter Px4-300d
Subscribe
Storcenter Px4-300d Firmware
Subscribe
Storcenter Px4-300r
Subscribe
Storcenter Px4-300r Firmware
Subscribe
Storcenter Px6-300d
Subscribe
Storcenter Px6-300d Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20682 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24224 |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T07:17:50.623Z
Reserved: 2018-03-27T00:00:00
Link: CVE-2018-9079
No data.
Status : Modified
Published: 2018-09-28T20:29:01.207
Modified: 2024-11-21T04:14:55.907
Link: CVE-2018-9079
No data.
OpenCVE Enrichment
No data.
EUVD