ZeroHour

CVE-2018-9080

CVSS 3.0
5.9 medium
EPSS
<1%p52
Published
()
Modified
Description

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.

Vendors
lenovo
Products
storcenter px12-450r firmware, storcenter px12-400r firmware, storcenter px4-300r firmware, storcenter px6-300d firmware, storcenter px4-300d firmware, storcenter px2-300d firmware, storcenter ix4-300d firmware, storcenter ix2 firmware, storcenter ix2-dl firmware, ez media \& backup center firmware, px12-450r firmware, px12-400r firmware
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news