Description
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
Published: 2019-07-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to the firmware level (or later) described for your system in the Product Impact section of LEN-25557. If it is not feasible to update the firmware immediately, partial protection can be achieved by removing any public shares and using the device only on trusted networks.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-15727 A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
History

No history.

Subscriptions

Lenovo Home Media Network Hard Drive Home Media Network Hard Drive Firmware Ix12-300r Ix12-300r Firmware Px12-350r Px12-350r Firmware Storcenter Ix-200 Storcenter Ix2-200 Storcenter Ix2-200 Firmware Storcenter Ix4-200d Storcenter Ix4-200d Firmware Storcenter Ix4-200rl Storcenter Ix4-200rl Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-16T18:08:53.112Z

Reserved: 2019-01-11T00:00:00.000Z

Link: CVE-2019-6160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-07-16T19:15:13.127

Modified: 2024-11-21T04:46:03.290

Link: CVE-2019-6160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses