Lenovo confirms the vulnerability of its NAS devices
A Lenovo statement confirms the vulnerability of its NAS and recommends updating the firmware as soon as possible.
The security issues They are common within the computer industry. Specifically, a vulnerability has now been found in Lenovo NAS. It was the company's website that confirmed the problem. This vulnerability affects connected storage devices. A bug that exposes the data of all customers of this products to anyone who is looking for it.
This vulnerability is recognized after a report revealed the bug. This report indicates that more than 13 spreadsheets had been found indexed. The different spreadsheets, in most cases, contained sensitive data, such as financial data. A major problem for Lenovo, which deals with absolute transparency.
Lenovo confirmed the vulnerability of its NAS
The company has reported that the vulnerability allows an unidentified user to access the documents shared by the NAS through the API. Lenovo has specified the devices affected by this vulnerability. Specifically, the ruling affects 5 devices from the Lenovo company and its subsidiary Iomega, which are connected to the internet. Obviously the problem is extremely serious.
Some of the devices were already listed as 'End of Life', so they will not receive security patches. From Lenovo they have asked all customers to update the firmware as soon as possible. This guarantees security and prevents an external attacker from accessing the data.
Anyone with a Lenovo NAS or storage system will need to upgrade. If it is in the 'End of Life' catalog, the device should be changed as soon as possible. Buying a newer product or from QNAP, for example, with years of experience, will be best for your safety.
