CVE-2018-9074

MEDIUM

LenovoEMC Firmware < 4.1.402.34662 - Path Traversal and Arbitrary File Write via Content Explorer Upload

Title source: llm
STIX 2.1

Description

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/solutions/LEN-24224

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 57.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
lenovo/lenovoemc_firmware < 4.1.402.34662
Published Sep 28, 2018
Tracked Since Feb 18, 2026