CVE-2009-2367
critical · 9.8cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
9.8
CVSS
23.2%
EPSS (exploit prob.)
98th
EPSS percentile
2009-07-08
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-338
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| iomega | storcenter_pro_firmware | all versions |
| iomega | storcenter_pro | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/55586
- http://secunia.com/advisories/35666
- http://trac.metasploit.com/browser/framework3/trunk/modules/auxiliary/admin/http/iomega_storcenterpro_sessionid.rb?rev=6733
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51539
- http://osvdb.org/55586
- http://secunia.com/advisories/35666
- http://trac.metasploit.com/browser/framework3/trunk/modules/auxiliary/admin/http/iomega_storcenterpro_sessionid.rb?rev=6733
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51539
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-2367