PT-2018-18843 · Iomega+1 · Iomega+1
Publicado
2018-09-28
·
Atualizado
2019-01-07
·
CVE-2018-9082
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier
Description
The password changing functionality does not require the user's current password to set a new one, allowing attackers with access to the user's session tokens to change their password and retain access to the user's account.
Recommendations
For versions 4.1.402.34662 and earlier, consider disabling the password changing functionality until a fix is available, and restrict access to user accounts to minimize the risk of exploitation.
Correção
Session Fixation
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Iomega
Lenovoemc Nas