An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-15745 An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Fixes

Solution

To protect your device against this vulnerability, disable Personal Cloud. If Personal Cloud is enabled, avoid using sensitive share names and only use the device on trusted networks.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-17T02:37:09.217Z

Reserved: 2019-01-11T00:00:00

Link: CVE-2019-6178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-19T16:15:11.177

Modified: 2024-11-21T04:46:06.613

Link: CVE-2019-6178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.