LenovoEMC and Iomega NASÐÅϢй¶Îó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-18

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-6160£¬£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÒÔϲúÆ·ÊÜÓ°Ï죺px12-350r and ix12-300r£¬£¬ £¬£¬£¬£¬HMNHD Cloud Editiond£¬£¬ £¬£¬£¬£¬StorCenter ix2-200£¬£¬ £¬£¬£¬£¬StorCenter ix4-200d£¬£¬ £¬£¬£¬£¬StorCenter ix4-200rlµÈ¡£¡£¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


Lenovo Iomega StorCenter px12-350rµÈ¶¼ÊÇÖйúåÚÏ루Lenovo£©¹«Ë¾µÄ´æ´¢×°±¸¡£¡£¡£¡£¡£¡£¡£ 


CVE-2019-6160Ó°ÏìÁËÐí¶àIomegaºÍLenovoEMC NAS²úÆ·£¬£¬ £¬£¬£¬£¬ÕâЩ²úÆ·ÒÑÔÚËÄÄêǰµÖ´ïÁËЧÀÍÖյ㡣¡£¡£¡£¡£¡£¡£¹Å°åIomegaºÍLenovoEMCÍøÂçÅþÁ¬´æ´¢£¨NAS£©×°±¸ÖеÄÎó²îµ¼ÖÂÈκÎÈ˶¼¿ÉÒÔͨ¹ýInternet»á¼ûÐí¶àTBµÄDZÔÚÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


¸ÃÎó²îÔ´ÓÚ²»Êܱ£»£» £»£»£»£» £»¤µÄAPIŲÓ㬣¬ £¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§Í¨¹ýAPI»á¼ûNAS¹²ÏíÉϵÄÎļþ¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬£¬ £¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£º


px12-350r and ix12-300r, version 4.0.24.34808: 

http://download.lenovo.com/lenovoemc/eu/en/app/answers/detail/a_id/23142.html


HMNHD (Home Media Network Hard Drive) Cloud Editiond, version 3.2.16.30221: 

http://download.lenovo.com/lenovoemc/na/en/app/answers/detail/a_id/26791.html


StorCenter ix2-200, Cloud Edition, version 3.2.16.30221: 

http://download.lenovo.com/lenovoemc/na/en/app/answers/detail/a_id/26789.html


StorCenter ix4-200d, Cloud Edition, version 3.2.16.30221: 

http://download.lenovo.com/lenovoemc/na/en/app/answers/detail/a_id/26784.html


StorCenter ix2-200, version 2.1.50.30227: 

http://download.lenovo.com/lenovoemc/na/en/app/answers/detail/a_id/22318.html


StorCenter ix4-200d, version 2.1.50.30227: 

http://download.lenovo.com/lenovoemc/na/en/app/answers/detail/a_id/22315.html


StorCenter ix4-200rl, version 2.1.50.30227 :

http://download.lenovo.com/lenovoemc/na/en/app/answers/detail/a_id/29782.html¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.helpnetsecurity.com/2019/07/17/lenovoemc-nas-devices-flaw/