Описание
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
Ссылки
- Broken LinkExploit
- Broken LinkVendor Advisory
- Broken LinkExploit
- Third Party AdvisoryVDB Entry
- Broken LinkExploit
- Broken LinkVendor Advisory
- Broken LinkExploit
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
Одновременно
cpe:2.3:o:iomega:storcenter_pro_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:iomega:storcenter_pro:-:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.32334
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-338
Связанные уязвимости
CVSS3: 9.8
github
почти 4 года назад
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
EPSS
Процентиль: 97%
0.32334
Средний
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-338