Back to search
CVE-2018-9080
Published: Sep 28, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
| Vendor | Product | Versions |
|---|---|---|
Lenovo Group LTD | Iomega StorCenter | affected 4.1.402.34662 - <= 4.1.402.34662 |
Lenovo Group LTD | LenovoEMC | affected 4.1.402.34662 - <= 4.1.402.34662 |
Lenovo Group LTD | EZ Media and Backup Center | affected 4.1.402.34662 - <= 4.1.402.34662 |
References
https://support.lenovo.com/us/en/solutions/LEN-24224
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now