Iomega's vulnerability profile centers on a narrow range of network-attached storage and media-serving devices, including its home media network drives, iConnect appliances, and NAS firmware, which occupy a niche but persistent role in consumer and small-office deployments. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, while the recurring weakness classes—including cleartext transmission of sensitive information and weak cryptographic implementations—reflect the embedded and remote-access nature of these appliances. Defenders should prioritize inventory and network isolation of affected devices, particularly older models where firmware updates may be unavailable; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iomega over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2367CRITICAL cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing | Jul 8, 2009 | 9.8 | 48 | NO | YES |
CVE-2001-0110HIGH Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environmental variable. | Mar 12, 2001 | 7.2 | 27 | NO | YES |
CVE-2012-2283MEDIUM The Iomega Home Media Network Hard Drive with EMC Lifeline firmware before 2.104, Home Media Network Hard Drive Cloud Edition with EMC Lifeline firmware before 3.2.3.15290, iConnec | Aug 16, 2012 | 5.5 | 19 | NO | NO |
CVE-2002-1949HIGH The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sniff the administrative password | Dec 31, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-1955MEDIUM Iomega NAS A300U uses cleartext LANMAN authentication when mounting CIFS/SMB drives, which allows remote attackers to perform a man-in-the-middle attack. | Dec 31, 2002 | 5.0 | 15 | NO | NO |
CVE-2002-1863MEDIUM Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP e | Dec 31, 2002 | 4.6 | 14 | NO | NO |
CVE-1999-1174MEDIUM ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the | Dec 21, 2001 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iomega.
Media articles that mention a CVE ID that affects a product developed by Iomega — matched by CVE ID, not by vendor name.