CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.9. See the original NVD description below for full technical details.
CVE
CVE-2018-9080
Severity
MEDIUM
CVSS
5.9
EPSS
0.73%
Original NVD Description
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, by setting the Iomega cookie to a known value before logging into the NAS's web application, the NAS will not provide the user a new cookie value. This allows an attacker who knows the cookie's value to compromise the user's session.
Related CVEs
Other vulnerabilities affecting the same vendor(s)