Learn about CVE-2018-9080 affecting Iomega, Lenovo, and LenovoEMC NAS devices. Find out how attackers exploit session fixation to compromise user sessions and steps to prevent unauthorized access.
A vulnerability in certain versions of Iomega, Lenovo, and LenovoEMC NAS devices allows attackers to compromise user sessions by exploiting session fixation.
Understanding CVE-2018-9080
What is CVE-2018-9080?
The CVE-2018-9080 vulnerability affects versions 4.1.402.34662 and earlier of Iomega StorCenter, LenovoEMC, and EZ Media and Backup Center NAS devices. Attackers can exploit this vulnerability to compromise user sessions.
The Impact of CVE-2018-9080
By manipulating the Iomega cookie value before logging into the NAS web application, attackers can gain unauthorized access to user sessions, potentially leading to data breaches and unauthorized actions.
Technical Details of CVE-2018-9080
Vulnerability Description
The vulnerability arises from the NAS devices' failure to generate a new cookie when the Iomega cookie is set to a specific value, allowing attackers with knowledge of the cookie's value to compromise user sessions.
Affected Systems and Versions
Exploitation Mechanism
Attackers exploit the vulnerability by setting the Iomega cookie to a predetermined value before logging into the NAS web application, causing the NAS to fail in generating a new cookie, enabling session compromise.
Mitigation and Prevention
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates