Metrics
No CVSS v4.0
No CVSS v3.1
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact None
User Interaction Required
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
This CVE is not in the KEV list.
The EPSS score is 0.00301.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Lenovo
Subscribe
|
Ez Media \& Backup Center
Subscribe
Ez Media \& Backup Center Firmware
Subscribe
Ix2
Subscribe
Ix2 Firmware
Subscribe
Ix4-300d
Subscribe
Ix4-300d Firmware
Subscribe
Px12-400r
Subscribe
Px12-400r Firmware
Subscribe
Px12-450r
Subscribe
Px12-450r Firmware
Subscribe
Px2-300d
Subscribe
Px2-300d Firmware
Subscribe
Px4-300d
Subscribe
Px4-300d Firmware
Subscribe
Px4-300r
Subscribe
Px4-300r Firmware
Subscribe
Px4-400d
Subscribe
Px4-400d Firmware
Subscribe
Px4-400r
Subscribe
Px4-400r Firmware
Subscribe
Px6-300d
Subscribe
Px6-300d Firmware
Subscribe
Storcenter Ix2
Subscribe
Storcenter Ix2-dl
Subscribe
Storcenter Ix2-dl Firmware
Subscribe
Storcenter Ix2 Firmware
Subscribe
Storcenter Ix4-300d
Subscribe
Storcenter Ix4-300d Firmware
Subscribe
Storcenter Px12-400r
Subscribe
Storcenter Px12-400r Firmware
Subscribe
Storcenter Px12-450r
Subscribe
Storcenter Px12-450r Firmware
Subscribe
Storcenter Px2-300d
Subscribe
Storcenter Px2-300d Firmware
Subscribe
Storcenter Px4-300d
Subscribe
Storcenter Px4-300d Firmware
Subscribe
Storcenter Px4-300r
Subscribe
Storcenter Px4-300r Firmware
Subscribe
Storcenter Px6-300d
Subscribe
Storcenter Px6-300d Firmware
Subscribe
|
Configuration 1 [-]
| AND |
|
Configuration 2 [-]
| AND |
|
Configuration 3 [-]
| AND |
|
Configuration 4 [-]
| AND |
|
Configuration 5 [-]
| AND |
|
Configuration 6 [-]
| AND |
|
Configuration 7 [-]
| AND |
|
Configuration 8 [-]
| AND |
|
Configuration 9 [-]
| AND |
|
Configuration 10 [-]
| AND |
|
Configuration 11 [-]
| AND |
|
Configuration 12 [-]
| AND |
|
Configuration 13 [-]
| AND |
|
Configuration 14 [-]
| AND |
|
Configuration 15 [-]
| AND |
|
Configuration 16 [-]
| AND |
|
Configuration 17 [-]
| AND |
|
Configuration 18 [-]
| AND |
|
Configuration 19 [-]
| AND |
|
Configuration 20 [-]
| AND |
|
Configuration 21 [-]
| AND |
|
No data.
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-20684 | For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24224 |
|
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: lenovo
Published:
Updated: 2024-08-05T07:17:50.658Z
Reserved: 2018-03-27T00:00:00
Link: CVE-2018-9081
No data.
Status : Modified
Published: 2018-09-28T20:29:01.423
Modified: 2024-11-21T04:14:56.240
Link: CVE-2018-9081
No data.
OpenCVE Enrichment
No data.
EUVD