CVE-2018-9080: Iomega and LenovoEMC NAS Web UI Vulnerabilities
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-9080?
CVE-2018-9080 is considered a medium-risk vulnerability due to its potential for session fixation attacks.
How do I fix CVE-2018-9080?
To fix CVE-2018-9080, update the firmware of your Lenovo and Iomega NAS devices to versions later than 4.1.402.34662.
Which devices are affected by CVE-2018-9080?
CVE-2018-9080 affects Lenovo Storcenter Px12-450r, Px12-400r, Px4-300r, Px6-300d, Px2-300d, and similar NAS devices with firmware version 4.1.402.34662.
What type of attack does CVE-2018-9080 facilitate?
CVE-2018-9080 enables session fixation attacks by allowing an attacker to set a known cookie value before user login.
Is CVE-2018-9080 easily exploitable?
Yes, CVE-2018-9080 is easily exploitable if an attacker can access the NAS web application, making it critical to implement protective measures.