High severity8.8NVD Advisory· Published Jul 16, 2019· Updated Jun 17, 2026
CVE-2019-6160
CVE-2019-6160
Description
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
Affected products
11- cpe:2.3:o:lenovo:home_media_network_hard_drive_firmware:*:*:*:*:cloud:*:*:*Range: <3.2.16.30221
cpe:2.3:o:lenovo:storcenter_ix2-200_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:lenovo:storcenter_ix2-200_firmware:*:*:*:*:*:*:*:*range: <2.1.50.30227
- cpe:2.3:o:lenovo:storcenter_ix2-200_firmware:*:*:*:*:cloud:*:*:*range: <3.2.16.30221
cpe:2.3:o:lenovo:storcenter_ix4-200d_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:lenovo:storcenter_ix4-200d_firmware:*:*:*:*:*:*:*:*range: <2.1.50.30227
- cpe:2.3:o:lenovo:storcenter_ix4-200d_firmware:*:*:*:*:cloud:*:*:*range: <3.2.16.30221
- cpe:2.3:o:lenovo:storcenter_ix4-200rl_firmware:*:*:*:*:*:*:*:*Range: <2.1.50.30227
- Iomega and LenovoEMC/NAS productsv5Range: various
Patches
Vulnerability mechanics
References
1- support.lenovo.com/solutions/LEN-25557nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.