First published: Wed Jul 08 2009(Updated: )
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Iomega StorCenter Pro Firmware | ||
Iomega StorCenter Pro Firmware | ||
Iomega StorCenter Pro Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-2367 is classified as medium due to the potential for session hijacking.
To fix CVE-2009-2367, update the Iomega StorCenter Pro to the latest firmware version that addresses session ID vulnerability.
CVE-2009-2367 affects users of Iomega StorCenter Pro and its firmware versions that generate predictable session IDs.
CVE-2009-2367 is a session fixation vulnerability allowing attackers to hijack user sessions.
Yes, CVE-2009-2367 can be exploited remotely, allowing attackers to gain privileges through brute force attacks.