Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2019-6160

Disclosure Date: July 16, 2019 (last updated November 27, 2024)
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
0
Attacker Value
Unknown

Iomega and LenovoEMC NAS Web UI Vulnerabilities

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account
0
Attacker Value
Unknown

Iomega and LenovoEMC NAS Web UI Vulnerabilities

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
0
Attacker Value
Unknown

Iomega and LenovoEMC NAS Web UI Vulnerabilities

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
0
Attacker Value
Unknown

Iomega and LenovoEMC NAS Web UI Vulnerabilities

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
0
Attacker Value
Unknown

Iomega and LenovoEMC NAS Web UI Vulnerabilities

Disclosure Date: September 28, 2018 (last updated November 27, 2024)
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.
0
Attacker Value
Unknown

CVE-2012-2283

Disclosure Date: August 16, 2012 (last updated October 04, 2023)
The Iomega Home Media Network Hard Drive with EMC Lifeline firmware before 2.104, Home Media Network Hard Drive Cloud Edition with EMC Lifeline firmware before 3.2.3.15290, iConnect with EMC Lifeline firmware before 2.5.26.18966, and StorCenter with EMC Lifeline firmware before 2.0.18.23122, 2.1.x before 2.1.42.18967, and 3.x before 3.2.3.15290 allow remote authenticated users to read or modify data on arbitrary remote shares via unspecified vectors.
0
Attacker Value
Unknown

CVE-2009-2367

Disclosure Date: July 08, 2009 (last updated February 10, 2024)
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.