CVE-2018-9080

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
References
Configurations

Configuration 1


Information

Published : 2018-09-28 08:29

Updated : 2019-01-08 12:19


NVD link : CVE-2018-9080

Mitre link : CVE-2018-9080

Products Affected
No products.
CWE