Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Thousands of Legacy Lenovo Storage Devices Exposed Millions of Files

Cybersecurity firms Vertical Structure and WhiteHat Security on Tuesday reported that their researchers discovered a serious vulnerability that gave remote attackers access to millions of files stored on thousands of exposed Lenovo network-attached storage (NAS) devices.

Cybersecurity firms Vertical Structure and WhiteHat Security on Tuesday reported that their researchers discovered a serious vulnerability that gave remote attackers access to millions of files stored on thousands of exposed Lenovo network-attached storage (NAS) devices.

An analysis revealed that the exposed devices were discontinued Iomega/LenovoEMC storage products. Simon Whittaker, director at Vertical Structure, told SecurityWeek that a Shodan search conducted in the fall of 2018 revealed 5,114 devices storing over 3 million files. This includes roughly 20,000 documents, 13,000 spreadsheets, 13,000 text files and 405,000 pictures. Some of the files stored sensitive information, including payment card numbers and financial records.

Whittaker believes the actual number of exposed systems is likely higher as the 5,114 devices are only the ones that were identified and had some details indexed.

The vulnerability could have been exploited by a remote, unauthenticated attacker to gain access to the files stored on the devices by sending a specially crafted request via an API.

“The API is completely unauthenticated and provided the ability to list, access and retrieve the files remotely in a trivial manner. It is similar to millions of open s3 buckets being discovered,” Whittaker told SecurityWeek.

An attacker could have scanned the web for vulnerable devices and sent a malicious request to the targeted device’s IP address. However, Whittaker said an attacker could have also created a script that would automate the attack and retrieve data from all the vulnerable devices.

Advertisement. Scroll to continue reading.

Vertical Structure and WhiteHat reported their findings to Lenovo, which pulled three versions of the affected software out of retirement to address the vulnerability. Lenovo, which tracks the flaw as CVE-2019-6160, published an advisory on Tuesday.

This is not the first time Lenovo has warned users about a potentially serious vulnerability affecting its discontinued Iomega and LenovoEMC NAS products. Last year, the company learned of nine weaknesses, including ones that could have been chained to completely compromise a device.

*Updated with CVE and link to Lenovo advisory

Related: Backdoor Found in Lenovo, IBM Switches

Related: Lenovo Patches Critical Wi-Fi Vulnerabilities

Related: Nine Remotely Exploitable Vulnerabilities Found in Dell EMC Storage Platform

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Chip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.

Lumen Technologies has named Kim Keever as CSO.

Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.