CVE-2019-6160: Lenovo Home Media Network Hard Drive Firmware
High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.
A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.
Affected products
- Lenovo Home Media Network Hard Drive Firmware: before 3.2.16.30221 (fixed in 3.2.16.30221)
- Lenovo IX12-300r Firmware: before 4.0.24.34808 (fixed in 4.0.24.34808)
- Lenovo PX12-350r Firmware: before 4.0.24.34808 (fixed in 4.0.24.34808)
- Lenovo Storcenter IX2-200 Firmware: before 3.2.16.30221 (fixed in 3.2.16.30221); before 2.1.50.30227 (fixed in 2.1.50.30227)
- Lenovo Storcenter IX4-200d Firmware: before 3.2.16.30221 (fixed in 3.2.16.30221); before 2.1.50.30227 (fixed in 2.1.50.30227)
- Lenovo Storcenter IX4-200rl Firmware: before 2.1.50.30227 (fixed in 2.1.50.30227)
Published 2019-07-16. Last modified 2026-06-17.