CVE-2018-11741: Infoleak
Published Dec 26, 2018
·Updated
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.
Affected Software
2 affected components
NEC Univerge Sv9100 Webpro Firmware=6.00.00
NEC Univerge Sv9100 WebPro
Event History
Dec 26, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11741?
CVE-2018-11741 has been classified with a medium severity level due to the risk of account information disclosure.
2
How do I fix CVE-2018-11741?
To fix CVE-2018-11741, upgrade the NEC Univerge Sv9100 WebPro to a version that does not utilize predictable session IDs.
3
What type of vulnerability is CVE-2018-11741?
CVE-2018-11741 is a vulnerability that involves predictable session IDs leading to account information disclosure.
4
Which software is affected by CVE-2018-11741?
The affected software for CVE-2018-11741 is the NEC Univerge Sv9100 WebPro firmware version 6.00.00.
5
Can CVE-2018-11741 impact security in my organization?
Yes, CVE-2018-11741 can impact your organization's security by potentially allowing unauthorized access to user accounts.