CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
34.8%
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file name used for assets accessible through the Content Viewer application are vulnerable to self cross-site scripting self-XSS. As a result, adversaries can add files to shares accessible from the Content Viewer with a cross site scripting payload in its name, and wait for a user to try and rename the file for their payload to trigger.
Vendor | Product | Version | CPE |
---|---|---|---|
lenovo | storcenter_px12-450r_firmware | 4.1.402.34662 | cpe:2.3:o:lenovo:storcenter_px12-450r_firmware:4.1.402.34662:*:*:*:*:*:*:* |
lenovo | storcenter_px12-450r | - | cpe:2.3:h:lenovo:storcenter_px12-450r:-:*:*:*:*:*:*:* |
lenovo | storcenter_px12-400r_firmware | 4.1.402.34662 | cpe:2.3:o:lenovo:storcenter_px12-400r_firmware:4.1.402.34662:*:*:*:*:*:*:* |
lenovo | storcenter_px12-400r | - | cpe:2.3:h:lenovo:storcenter_px12-400r:-:*:*:*:*:*:*:* |
lenovo | storcenter_px4-300r_firmware | 4.1.402.34662 | cpe:2.3:o:lenovo:storcenter_px4-300r_firmware:4.1.402.34662:*:*:*:*:*:*:* |
lenovo | storcenter_px4-300r | - | cpe:2.3:h:lenovo:storcenter_px4-300r:-:*:*:*:*:*:*:* |
lenovo | storcenter_px6-300d_firmware | 4.1.402.34662 | cpe:2.3:o:lenovo:storcenter_px6-300d_firmware:4.1.402.34662:*:*:*:*:*:*:* |
lenovo | storcenter_px6-300d | - | cpe:2.3:h:lenovo:storcenter_px6-300d:-:*:*:*:*:*:*:* |
lenovo | storcenter_px4-300d_firmware | 4.1.402.34662 | cpe:2.3:o:lenovo:storcenter_px4-300d_firmware:4.1.402.34662:*:*:*:*:*:*:* |
lenovo | storcenter_px4-300d | - | cpe:2.3:h:lenovo:storcenter_px4-300d:-:*:*:*:*:*:*:* |
[
{
"product": "Iomega StorCenter",
"vendor": "Lenovo Group LTD",
"versions": [
{
"lessThanOrEqual": "4.1.402.34662",
"status": "affected",
"version": "4.1.402.34662",
"versionType": "custom"
}
]
},
{
"product": "LenovoEMC",
"vendor": "Lenovo Group LTD",
"versions": [
{
"lessThanOrEqual": "4.1.402.34662",
"status": "affected",
"version": "4.1.402.34662",
"versionType": "custom"
}
]
},
{
"product": "EZ Media and Backup Center",
"vendor": "Lenovo Group LTD",
"versions": [
{
"lessThanOrEqual": "4.1.402.34662",
"status": "affected",
"version": "4.1.402.34662",
"versionType": "custom"
}
]
}
]
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:H/Au:N/C:N/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
34.8%