CVE-2018-9082

HIGH

Iomega LenovoEMC NAS <4.1.402.34662 - Privilege Escalation

Title source: llm
STIX 2.1

Description

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://support.lenovo.com/us/en/solutions/LEN-24224

Scores

CVSS v3 8.8
EPSS 0.0020
EPSS Percentile 41.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (20)
lenovo/ez_media_\&_backup_center_firmware 4.1.402.34662
lenovo/ix2_firmware 4.1.402.34662
lenovo/ix4-300d_firmware 4.1.402.34662
lenovo/px12-400r_firmware 4.1.402.34662
lenovo/px12-450r_firmware 4.1.402.34662
lenovo/px2-300d_firmware 4.1.402.34662
lenovo/px4-300d_firmware 4.1.402.34662
lenovo/px4-300r_firmware 4.1.402.34662
lenovo/px4-400d_firmware 4.1.402.34662
lenovo/px4-400r_firmware 4.1.402.34662
... and 10 more
Published Sep 28, 2018
Tracked Since Feb 18, 2026