First published: Fri Sep 28 2018(Updated: )
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
Credit: psirt@lenovo.com
Affected Software | Affected Version | How to fix |
---|---|---|
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo StorCenter PX12-450R Firmware | ||
Lenovo PX12-400R | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo StorCenter PX4-300R | =4.1.402.34662 | |
Lenovo Storcenter PX4-300R Firmware | ||
Lenovo PX6-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX6-300D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX4-300D | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter PX2-300D | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo Storcenter IX4-300D Firmware | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo Iomega StorCenter ix2-dl | ||
Lenovo StorCenter ix2-dl | =4.1.402.34662 | |
Lenovo StorCenter ix2-dl Firmware | ||
Lenovo EZ Media & Backup Center Firmware | =4.1.402.34662 | |
Lenovo Ez Media & Backup Center | ||
Lenovo Storcenter PX12-450R | =4.1.402.34662 | |
Lenovo EMC px12-400r/450r | ||
Lenovo Storcenter PX12-400R Firmware | =4.1.402.34662 | |
Lenovo Storage Center PX12-400R | ||
Lenovo px4-400r | =4.1.402.34662 | |
Lenovo EMC px4-400r | ||
Lenovo Storcenter PX4-300R Firmware | =4.1.402.34662 | |
Lenovo StorCenter PX4-300R | ||
Lenovo StorCenter PX6-300D Firmware | =4.1.402.34662 | |
Lenovo EMC PX6-300D | ||
Lenovo PX4-400D | =4.1.402.34662 | |
Lenovo PX4-400D | ||
Lenovo Storcenter PX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px4-300d | ||
Lenovo Storcenter PX2-300D Firmware | =4.1.402.34662 | |
Lenovo EMC px2-300d | ||
Lenovo Storcenter IX4-300D Firmware | =4.1.402.34662 | |
Lenovo EMC ix4-300d | ||
Lenovo Storage IX2 Firmware | =4.1.402.34662 | |
Lenovo ix2 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-9080 is considered a medium-risk vulnerability due to its potential for session fixation attacks.
To fix CVE-2018-9080, update the firmware of your Lenovo and Iomega NAS devices to versions later than 4.1.402.34662.
CVE-2018-9080 affects Lenovo Storcenter Px12-450r, Px12-400r, Px4-300r, Px6-300d, Px2-300d, and similar NAS devices with firmware version 4.1.402.34662.
CVE-2018-9080 enables session fixation attacks by allowing an attacker to set a known cookie value before user login.
Yes, CVE-2018-9080 is easily exploitable if an attacker can access the NAS web application, making it critical to implement protective measures.