First published: Wed Dec 26 2018(Updated: )
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nec Univerge Sv9100 Webpro Firmware | =6.00.00 | |
NEC Univerge Sv9100 WebPro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11741 has been classified with a medium severity level due to the risk of account information disclosure.
To fix CVE-2018-11741, upgrade the NEC Univerge Sv9100 WebPro to a version that does not utilize predictable session IDs.
CVE-2018-11741 is a vulnerability that involves predictable session IDs leading to account information disclosure.
The affected software for CVE-2018-11741 is the NEC Univerge Sv9100 WebPro firmware version 6.00.00.
Yes, CVE-2018-11741 can impact your organization's security by potentially allowing unauthorized access to user accounts.