Description
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Published: 2019-08-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

To protect your device against this vulnerability, disable Personal Cloud. If Personal Cloud is enabled, avoid using sensitive share names and only use the device on trusted networks.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-15745 An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
History

No history.

Subscriptions

Lenovo Home Media Network Hard Drive Home Media Network Hard Drive Firmware Ix12-300r Ix12-300r Firmware Px12-350r Px12-350r Firmware Storecenter Ix2-200 Storecenter Ix2-200 Firmware Storecenter Ix4-200d Storecenter Ix4-200d Firmware Storecenter Ix4-200rl Storecenter Ix4-200rl Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: lenovo

Published:

Updated: 2024-09-17T02:37:09.217Z

Reserved: 2019-01-11T00:00:00.000Z

Link: CVE-2019-6178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-19T16:15:11.177

Modified: 2024-11-21T04:46:06.613

Link: CVE-2019-6178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses