Логотип exploitDog
bind:CVE-2018-9082
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-9082

Количество 2

Количество 2

nvd логотип

CVE-2018-9082

больше 7 лет назад

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-f5rx-9g37-6p6r

больше 3 лет назад

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-9082

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

CVSS3: 8.8
0%
Низкий
больше 7 лет назад
github логотип
GHSA-f5rx-9g37-6p6r

For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, the password changing functionality available to authenticated users does not require the user's current password to set a new one. As a result, attackers with access to the user's session tokens can change their password and retain access to the user's account

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу