Breaking News

Viltrox announces Seven-inch Camera Monitor the DC-A1 AMD Introduces New Radeon Graphics Cards and Ryzen Threadripper Processors at COMPUTEX 2025 COLORFUL Presents iGame Origo Series Laptops Lexar Introduces Innovative Product Lines at Computex 2025 Asus at Computex 2025

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Lenovo Vulnerability Left 36TB of Data Exposed

Lenovo Vulnerability Left 36TB of Data Exposed

Enterprise & IT Jul 17,2019 0

Security researchers from Vertical Structure and WhiteHat Security worked together to identify and verify a vulnerability in Lenovo-EMC storage products that left users of specific network-attached storage devices with 36TB of data exposed to anyone who went looking for it.

The researchers found "about 13,000 spreadsheet files indexed, with 36TB of data available. The number of files in the index from scanning totaled 3,030,106." Within these files, the report reveals, a "significant amount" with sensitive financial information including card numbers and financial records were found.

Lenovo has issued a security advisory which confirms that the firmware vulnerability "could allow an unauthenticated user to access files on NAS shares via the API." According to the researchers, it was "trivially easy" to exploit that application programming interface (API) and allow attackers to access the data stored upon any of several Lenovo-EMC network-attached storage (NAS) devices.

The investigation revealed at least 5,114 Iomega and LenovoEMC NAS devices connected to the Internet. It also appears that several of the impacted models had already reached end-of-life status, which meant that Lenovo no longer officially supported them.

The security researchers reported the issue to Lenovo. In response, Lenovo brought three obsolete versions of the device software back to enable customers to be able to continue using the devices while a patch was developed. "Lenovo's professional approach to vulnerability disclosure offers a good lesson for other organizations who experience similar challenges," the researchers said, continuing "not only did they have a clearly stated vulnerability disclosure policy on their site with contact information, but they responded quickly and worked with WhiteHat and Vertical Structure to understand the nature of the problem and quickly resolve it."

Further details about the vulnerability and Lenovo's resolution are available at Lenovo's Website.

If you have one of the devices concerned, then Lenovo is urging that you update the firmware as a matter of urgency.

Tags: CybersecurityLenovo
Previous Post
Patriot Launches The P200 Series SATA SSDs
Next Post
European Commission Opens Investigation Into Amazon

Related Posts

  • All New Lenovo ThinkStation PGX

  • Lenovo at CES 2025

  • Leica completes trinity series for the SL-System

  • Lenovo AI-Driven Devices

  • Micron Delivers Crucial LPCAMM2 with LPDDR5X Memory for the New AI-Ready Lenovo ThinkPad P1 Gen 7 Workstation

  • Lenovo at CES 2024

  • Lenovo Unlocks New AI PC Experiences with ThinkPad and IdeaPad Laptops Powered by Intel Core Ultra Processors

  • Available Now – Lenovo ThinkPad X1 Fold

Latest News

Viltrox announces Seven-inch Camera Monitor the DC-A1
Cameras

Viltrox announces Seven-inch Camera Monitor the DC-A1

AMD Introduces New Radeon Graphics Cards and Ryzen Threadripper Processors at COMPUTEX 2025
GPUs

AMD Introduces New Radeon Graphics Cards and Ryzen Threadripper Processors at COMPUTEX 2025

COLORFUL Presents iGame Origo Series Laptops
Enterprise & IT

COLORFUL Presents iGame Origo Series Laptops

Lexar Introduces Innovative Product Lines at Computex 2025
Cameras

Lexar Introduces Innovative Product Lines at Computex 2025

Asus at Computex 2025
GPUs

Asus at Computex 2025

Popular Reviews

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Dark Rock 5

be quiet! Dark Rock 5

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

G.skill Trident Z5 Neo RGB DDR5-6000 64GB CL30

Arctic Liquid Freezer III 420 - 360

Arctic Liquid Freezer III 420 - 360

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial Pro OC 32GB DDR5-6000 CL36 White

Crucial T705 2TB NVME White

Crucial T705 2TB NVME White

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed