8.8

CVE-2018-9078

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the Content Explorer application grants users the ability to upload files to shares and this image was rendered in the browser in the device's origin instead of prompting to download the asset. The application does not prevent the user from uploading SVG images and returns these images within their origin. As a result, malicious users can upload SVG images that contain arbitrary JavaScript that is evaluated when the victim issues a request to download the file.

Data is provided by the National Vulnerability Database (NVD)
LenovoStorcenter Px12-450r Firmware Version4.1.402.34662
   LenovoStorcenter Px12-450r Version-
LenovoStorcenter Px12-400r Firmware Version4.1.402.34662
   LenovoStorcenter Px12-400r Version-
LenovoStorcenter Px4-300r Firmware Version4.1.402.34662
   LenovoStorcenter Px4-300r Version-
LenovoStorcenter Px6-300d Firmware Version4.1.402.34662
   LenovoStorcenter Px6-300d Version-
LenovoStorcenter Px4-300d Firmware Version4.1.402.34662
   LenovoStorcenter Px4-300d Version-
LenovoStorcenter Px2-300d Firmware Version4.1.402.34662
   LenovoStorcenter Px2-300d Version-
LenovoStorcenter Ix4-300d Firmware Version4.1.402.34662
   LenovoStorcenter Ix4-300d Version-
LenovoStorcenter Ix2 Firmware Version4.1.402.34662
   LenovoStorcenter Ix2 Version-
LenovoStorcenter Ix2-dl Firmware Version4.1.402.34662
   LenovoStorcenter Ix2-dl Version-
LenovoEz Media & Backup Center Firmware Version4.1.402.34662
   LenovoEz Media & Backup Center Version-
LenovoPx12-450r Firmware Version4.1.402.34662
   LenovoPx12-450r Version-
LenovoPx12-400r Firmware Version4.1.402.34662
   LenovoPx12-400r Version-
LenovoPx4-400r Firmware Version4.1.402.34662
   LenovoPx4-400r Version-
LenovoPx4-300r Firmware Version4.1.402.34662
   LenovoPx4-300r Version-
LenovoPx6-300d Firmware Version4.1.402.34662
   LenovoPx6-300d Version-
LenovoPx4-400d Firmware Version4.1.402.34662
   LenovoPx4-400d Version-
LenovoPx4-300d Firmware Version4.1.402.34662
   LenovoPx4-300d Version-
LenovoPx2-300d Firmware Version4.1.402.34662
   LenovoPx2-300d Version-
LenovoIx4-300d Firmware Version4.1.402.34662
   LenovoIx4-300d Version-
LenovoIx2 Firmware Version4.1.402.34662
   LenovoIx2 Version-
LenovoEz Media & Backup Center Firmware Version4.1.402.34662
   LenovoEz Media & Backup Center Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.47% 0.617
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.