Vulnerability Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Lenovoemc Firmware | <= 4.1.402.34662 |
| Lenovo | Iomega Ez Media \& Backup Center | - |
| Lenovo | Iomega Storcenter Ix2 | - |
| Lenovo | Iomega Storcenter Ix2-Dl | - |
| Lenovo | Iomega Storcenter Ix4-300D | - |
| Lenovo | Iomega Storcenter Px12-400R | - |
| Lenovo | Iomega Storcenter Px12-450R | - |
| Lenovo | Iomega Storcenter Px2-300D | - |
| Lenovo | Iomega Storcenter Px4-300D | - |
| Lenovo | Iomega Storcenter Px4-300R | - |
| Lenovo | Iomega Storcenter Px6-300D | - |
| Lenovo | Lenovo Ez Media \& Backup Center | - |
| Lenovo | Lenovo Ix2 | - |
| Lenovo | Lenovo Ix4-300D | - |
| Lenovo | Lenovoemc Px12-400R | - |
| Lenovo | Lenovoemc Px12-450R | - |
| Lenovo | Lenovoemc Px2-300D | - |
| Lenovo | Lenovoemc Px4-300D | - |
| Lenovo | Lenovoemc Px4-300R | - |
| Lenovo | Lenovoemc Px4-400D | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/LEN-24224Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-24224Vendor Advisory
FAQ
What is CVE-2018-9074?
CVE-2018-9074 is a vulnerability with a CVSS score of 6.5 (MEDIUM). For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users...
How severe is CVE-2018-9074?
CVE-2018-9074 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9074?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Lenovoemc Firmware, Lenovo Iomega Ez Media \& Backup Center, Lenovo Iomega Storcenter Ix2, Lenovo Iomega Storcenter Ix2-Dl, Lenovo Iomega Storcenter Ix4-300D.