CVE-2009-2367: Weak RNG
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the sessionid parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2367?
The severity of CVE-2009-2367 is classified as medium due to the potential for session hijacking.
How do I fix CVE-2009-2367?
To fix CVE-2009-2367, update the Iomega StorCenter Pro to the latest firmware version that addresses session ID vulnerability.
Who is affected by CVE-2009-2367?
CVE-2009-2367 affects users of Iomega StorCenter Pro and its firmware versions that generate predictable session IDs.
What type of vulnerability is CVE-2009-2367?
CVE-2009-2367 is a session fixation vulnerability allowing attackers to hijack user sessions.
Can CVE-2009-2367 be exploited remotely?
Yes, CVE-2009-2367 can be exploited remotely, allowing attackers to gain privileges through brute force attacks.