5.3

CVE-2019-6178

An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lenovo ≫ Px12-350r Firmware Version 4.0.24.34808
   Lenovo ≫ Px12-350r Version -
Lenovo ≫ Ix12-300r Firmware Version 4.0.24.34808
   Lenovo ≫ Ix12-300r Version -
Lenovo ≫ Home Media Network Hard Drive Firmware Version 3.2.16.30221 SwEdition cloud
   Lenovo ≫ Home Media Network Hard Drive Version - SwEdition cloud
Lenovo ≫ Storecenter Ix2-200 Firmware Version 3.2.16.30221 SwEdition cloud
   Lenovo ≫ Storecenter Ix2-200 Version - SwEdition cloud
Lenovo ≫ Storecenter Ix4-200d Firmware Version 3.2.16.30221 SwEdition cloud
   Lenovo ≫ Storecenter Ix4-200d Version - SwEdition cloud
Lenovo ≫ Storecenter Ix2-200 Firmware Version 2.1.50.30227
   Lenovo ≫ Storecenter Ix2-200 Version -
Lenovo ≫ Storecenter Ix4-200d Firmware Version 2.1.50.30227
   Lenovo ≫ Storecenter Ix4-200d Version -
Lenovo ≫ Storecenter Ix4-200rl Firmware Version 2.1.50.30227
   Lenovo ≫ Storecenter Ix4-200rl Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.1% 0.613
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Lenovo 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://support.lenovo.com/solutions/LEN-25557
Vendor Advisory