Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-6178


An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.


Published

2019-08-19T16:15:11.177

Last Modified

2024-11-21T04:46:06.613

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System lenovo px12-350r_firmware 4.0.24.34808 Yes
Hardware lenovo px12-350r - No
Operating System lenovo ix12-300r_firmware 4.0.24.34808 Yes
Hardware lenovo ix12-300r - No
Operating System lenovo home_media_network_hard_drive_firmware 3.2.16.30221 Yes
Hardware lenovo home_media_network_hard_drive - No
Operating System lenovo storecenter_ix2-200_firmware 3.2.16.30221 Yes
Hardware lenovo storecenter_ix2-200 - No
Operating System lenovo storecenter_ix4-200d_firmware 3.2.16.30221 Yes
Hardware lenovo storecenter_ix4-200d - No
Operating System lenovo storecenter_ix2-200_firmware 2.1.50.30227 Yes
Hardware lenovo storecenter_ix2-200 - No
Operating System lenovo storecenter_ix4-200d_firmware 2.1.50.30227 Yes
Hardware lenovo storecenter_ix4-200d - No
Operating System lenovo storecenter_ix4-200rl_firmware 2.1.50.30227 Yes
Hardware lenovo storecenter_ix4-200rl - No

References