CVE-2019-6178: Lenovo Home Media Network Hard Drive Firmware
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through the device API when Personal Cloud is enabled. This does not allow read, write, delete, or any other access to the underlying file systems and their contents.
Affected products
- Lenovo Home Media Network Hard Drive Firmware: version 3.2.16.30221 only
- Lenovo IX12-300r Firmware: version 4.0.24.34808 only
- Lenovo PX12-350r Firmware: version 4.0.24.34808 only
- Lenovo Storecenter IX2-200 Firmware: version 3.2.16.30221 only; version 2.1.50.30227 only
- Lenovo Storecenter IX4-200d Firmware: version 3.2.16.30221 only; version 2.1.50.30227 only
- Lenovo Storecenter IX4-200rl Firmware: version 2.1.50.30227 only
Published 2019-08-19. Last modified 2026-06-17.