CVE-2019-6178
Summary
| CVE | CVE-2019-6178 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-19 16:15:00 UTC |
| Updated | 2022-10-14 03:22:00 UTC |
| Description | An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Lenovo | Home Media Network Hard Drive | - | All | All | All |
| Hardware | Lenovo | Home Media Network Hard Drive | - | All | All | All |
| Operating System | Lenovo | Home Media Network Hard Drive Firmware | 3.2.16.30221 | All | All | All |
| Operating System | Lenovo | Home Media Network Hard Drive Firmware | 3.2.16.30221 | All | All | All |
| Hardware | Lenovo | Ix12-300r | - | All | All | All |
| Hardware | Lenovo | Ix12-300r | - | All | All | All |
| Operating System | Lenovo | Ix12-300r Firmware | 4.0.24.34808 | All | All | All |
| Operating System | Lenovo | Ix12-300r Firmware | 4.0.24.34808 | All | All | All |
| Hardware | Lenovo | Px12-350r | - | All | All | All |
| Hardware | Lenovo | Px12-350r | - | All | All | All |
| Operating System | Lenovo | Px12-350r Firmware | 4.0.24.34808 | All | All | All |
| Operating System | Lenovo | Px12-350r Firmware | 4.0.24.34808 | All | All | All |
| Hardware | Lenovo | Storecenter Ix2-200 | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix2-200 | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix2-200 | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix2-200 | - | All | All | All |
| Operating System | Lenovo | Storecenter Ix2-200 Firmware | 2.1.50.30227 | All | All | All |
| Operating System | Lenovo | Storecenter Ix2-200 Firmware | 3.2.16.30221 | All | All | All |
| Operating System | Lenovo | Storecenter Ix2-200 Firmware | 2.1.50.30227 | All | All | All |
| Operating System | Lenovo | Storecenter Ix2-200 Firmware | 3.2.16.30221 | All | All | All |
| Hardware | Lenovo | Storecenter Ix4-200d | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix4-200d | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix4-200d | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix4-200d | - | All | All | All |
| Operating System | Lenovo | Storecenter Ix4-200d Firmware | 2.1.50.30227 | All | All | All |
| Operating System | Lenovo | Storecenter Ix4-200d Firmware | 3.2.16.30221 | All | All | All |
| Operating System | Lenovo | Storecenter Ix4-200d Firmware | 2.1.50.30227 | All | All | All |
| Operating System | Lenovo | Storecenter Ix4-200d Firmware | 3.2.16.30221 | All | All | All |
| Hardware | Lenovo | Storecenter Ix4-200rl | - | All | All | All |
| Hardware | Lenovo | Storecenter Ix4-200rl | - | All | All | All |
| Operating System | Lenovo | Storecenter Ix4-200rl Firmware | 2.1.50.30227 | All | All | All |
| Operating System | Lenovo | Storecenter Ix4-200rl Firmware | 2.1.50.30227 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Iomega and LenovoEMC NAS Vulnerability - Lenovo Support US | MISC | support.lenovo.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Lenovo would like to thank Rafael Pedrero for reporting this issue.
There are currently no legacy QID mappings associated with this CVE.