Security Advisory

CVE-2018-9074

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-09-28 20:00:00
Last updated 2024-08-05 07:17:50
Assigner lenovo
CVSS score not scored
State PUBLISHED

Description

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the file upload functionality of the Content Explorer application is vulnerable to path traversal. As a result, users can upload files anywhere on the device's operating system as the root user.