Vulnerability Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lenovo | Storcenter Px12-450R Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Px12-450R | - |
| Lenovo | Storcenter Px12-400R Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Px12-400R | - |
| Lenovo | Storcenter Px4-300R Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Px4-300R | - |
| Lenovo | Storcenter Px6-300D Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Px6-300D | - |
| Lenovo | Storcenter Px4-300D Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Px4-300D | - |
| Lenovo | Storcenter Px2-300D Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Px2-300D | - |
| Lenovo | Storcenter Ix4-300D Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Ix4-300D | - |
| Lenovo | Storcenter Ix2 Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Ix2 | - |
| Lenovo | Storcenter Ix2-Dl Firmware | 4.1.402.34662 |
| Lenovo | Storcenter Ix2-Dl | - |
| Lenovo | Ez Media \& Backup Center Firmware | 4.1.402.34662 |
| Lenovo | Ez Media \& Backup Center | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/LEN-24224Vendor Advisory
- https://support.lenovo.com/us/en/solutions/LEN-24224Vendor Advisory
FAQ
What is CVE-2018-9080?
CVE-2018-9080 is a vulnerability with a CVSS score of 5.9 (MEDIUM). For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide...
How severe is CVE-2018-9080?
CVE-2018-9080 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-9080?
Check the references section above for vendor advisories and patch information. Affected products include: Lenovo Storcenter Px12-450R Firmware, Lenovo Storcenter Px12-450R, Lenovo Storcenter Px12-400R Firmware, Lenovo Storcenter Px12-400R, Lenovo Storcenter Px4-300R Firmware.