Iomega and LenovoEMC NAS Web UI Vulnerabilities
Published Sep 28, 2018
8.8
HIGHCVSS 3.0
EPSS 0.72%
Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account
Affected products
-
- Version 4.1.402.34662StatusaffectedConstraints<=4.1.402.34662
- Version
-
- Version 4.1.402.34662StatusaffectedConstraints<=4.1.402.34662
- Version
-
- Version 4.1.402.34662StatusaffectedConstraints<=4.1.402.34662
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Lenovo Group LTD | EZ Media and Backup Center | n/a |
| ||||||
| Lenovo Group LTD | Iomega StorCenter | n/a |
| ||||||
| Lenovo Group LTD | LenovoEMC | n/a |
|
Configuration 1
- 4.1.402.34662
Running on/with
- n/a
Configuration 2
- 4.1.402.34662
Running on/with
- n/a
Configuration 3
- 4.1.402.34662
Running on/with
- n/a
Configuration 4
- 4.1.402.34662
Running on/with
- n/a
Configuration 5
- 4.1.402.34662
Running on/with
- n/a
Configuration 6
- 4.1.402.34662
Running on/with
- n/a
Configuration 7
- 4.1.402.34662
Running on/with
- n/a
Configuration 8
- 4.1.402.34662
Running on/with
- n/a
Configuration 9
- 4.1.402.34662
Running on/with
- n/a
Configuration 10
- 4.1.402.34662
Running on/with
- n/a
Configuration 11
- 4.1.402.34662
Configuration 12
- 4.1.402.34662
Configuration 13
- 4.1.402.34662
Configuration 14
- 4.1.402.34662
Configuration 15
- 4.1.402.34662
Configuration 16
- 4.1.402.34662
Configuration 17
- 4.1.402.34662
Configuration 18
- 4.1.402.34662
Configuration 19
- 4.1.402.34662
Configuration 20
- 4.1.402.34662
Configuration 21
- 4.1.402.34662
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.72% (0.00719) | 52.15th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.72% (0.00719) | 52.39th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.10% (0.00104) | 43.04th | v3 (v2023.03.01) |
| Jun 28, 2024 | 0.10% (0.00104) | 42.91th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00104) | 40.90th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.42% (0.00416) | 10.04th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (1)
- https://support.lenovo.com/us/en/solutions/LEN-24224 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24224 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.