Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6ff8-jv2v-3qhh

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.

EPSS

Процентиль: 41%
0.00195
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.9
nvd
больше 7 лет назад

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.

EPSS

Процентиль: 41%
0.00195
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287