A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API
Published Jul 16, 2019
8.8
HIGHCVSS 3.0
EPSS 1.38%
Description
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
Affected products
-
- Version variousStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Iomega and LenovoEMC | NAS products | n/a |
|
Configuration 1
- < 4.0.24.34808
Configuration 2
- < 4.0.24.34808
Configuration 3
- < 3.2.16.30221
Running on/with
- n/a
Configuration 4
- < 3.2.16.30221
Running on/with
- n/a
Configuration 5
- < 3.2.16.30221
Running on/with
- n/a
Configuration 6
- < 2.1.50.30227
Running on/with
- n/a
Configuration 7
- < 2.1.50.30227
Running on/with
- n/a
Configuration 8
- < 2.1.50.30227
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update to the firmware level (or later) described for your system in the Product Impact section of LEN-25557. If it is not feasible to update the firmware immediately, partial protection can be achieved by removing any public shares and using the device only on trusted networks.
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15727 Advisory
- https://support.lenovo.com/solutions/LEN-25557 x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-15727 | Advisory | |
| https://support.lenovo.com/solutions/LEN-25557 | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.