Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2018-9079 Details
Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, adversaries can craft URLs to modify the Document Object Model (DOM) of the page. In addition, adversaries can inject HTML script tags and HTML tags with JavaScript handlers to execute arbitrary JavaScript with the origin of the device.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.lenovo.com/us/en/solutions/LEN-24224 | CVE | Vendor Advisory |
| https://support.lenovo.com/us/en/solutions/LEN-24224 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lenovo storcenter px12-450r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px12-450r | All versions |
CPE
Remediation
| |
| lenovo storcenter px12-400r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px12-400r | All versions |
CPE
Remediation
| |
| lenovo storcenter px4-300r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px4-300r | All versions |
CPE
Remediation
| |
| lenovo storcenter px6-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px6-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter px4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px4-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter px2-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter px2-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter ix4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter ix4-300d | All versions |
CPE
Remediation
| |
| lenovo storcenter ix2 firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter ix2 | All versions |
CPE
Remediation
| |
| lenovo storcenter ix2-dl firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo storcenter ix2-dl | All versions |
CPE
Remediation
| |
| lenovo ez media & backup center firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo ez media & backup center | All versions |
CPE
Remediation
| |
| lenovo px12-450r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px12-450r | All versions |
CPE
Remediation
| |
| lenovo px12-400r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px12-400r | All versions |
CPE
Remediation
| |
| lenovo px4-400r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-400r | All versions |
CPE
Remediation
| |
| lenovo px4-300r firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-300r | All versions |
CPE
Remediation
| |
| lenovo px6-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px6-300d | All versions |
CPE
Remediation
| |
| lenovo px4-400d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-400d | All versions |
CPE
Remediation
| |
| lenovo px4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px4-300d | All versions |
CPE
Remediation
| |
| lenovo px2-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo px2-300d | All versions |
CPE
Remediation
| |
| lenovo ix4-300d firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo ix4-300d | All versions |
CPE
Remediation
| |
| lenovo ix2 firmware | 4.1.402.34662 |
CPE
Remediation
| |
| lenovo ix2 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Jan 8, 2019 | Initial Analysis | [email protected] |