Vulnerability Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the name parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Lenovoemc Firmware | <= 4.1.402.34662 |
| Lenovo | Iomega Ez Media \& Backup Center | - |
| Lenovo | Iomega Storcenter Ix2 | - |
| Lenovo | Iomega Storcenter Ix2-Dl | - |
| Lenovo | Iomega Storcenter Ix4-300D | - |
| Lenovo | Iomega Storcenter Px12-400R | - |
| Lenovo | Iomega Storcenter Px12-450R | - |
| Lenovo | Iomega Storcenter Px2-300D | - |
| Lenovo | Iomega Storcenter Px4-300D | - |
| Lenovo | Iomega Storcenter Px4-300R | - |
| Lenovo | Iomega Storcenter Px6-300D | - |
| Lenovo | Lenovo Ez Media \& Backup Center | - |
| Lenovo | Lenovo Ix2 | - |
| Lenovo | Lenovo Ix4-300D | - |
| Lenovo | Lenovoemc Px12-400R | - |
| Lenovo | Lenovoemc Px12-450R | - |
| Lenovo | Lenovoemc Px2-300D | - |
| Lenovo | Lenovoemc Px4-300D | - |
| Lenovo | Lenovoemc Px4-300R | - |
| Lenovo | Lenovoemc Px4-400D | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/LEN-24224Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-24224Vendor Advisory
FAQ
What is CVE-2018-9076?
CVE-2018-9076 is a vulnerability with a CVSS score of 8.1 (HIGH). For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters i...
How severe is CVE-2018-9076?
CVE-2018-9076 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9076?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Lenovoemc Firmware, Lenovo Iomega Ez Media \& Backup Center, Lenovo Iomega Storcenter Ix2, Lenovo Iomega Storcenter Ix2-Dl, Lenovo Iomega Storcenter Ix4-300D.