CVE-2018-11741
Summary
| CVE | CVE-2018-11741 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-26 21:29:00 UTC |
| Updated | 2021-09-13 11:13:00 UTC |
| Description | NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Nec | Univerge Sv9100 Webpro | - | All | All | All |
| Operating System | Nec | Univerge Sv9100 Webpro Firmware | 6.00.00 | All | All | All |
| Hardware | Necom | Univerge Sv9100 Webpro | - | All | All | All |
| Hardware | Necom | Univerge Sv9100 Webpro | - | All | All | All |
| Operating System | Necom | Univerge Sv9100 Webpro Firmware | 6.00.00 | All | All | All |
| Operating System | Necom | Univerge Sv9100 Webpro Firmware | 6.00.00 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: CVE-2018-11741 / CVE-2018-11742 / NEC Univerge Sv9100 WebPro - 6.00 / Predictable Session ID / Clear Text Password Storage | FULLDISC | seclists.org | Exploit, Mailing List, Third Party Advisory |
| hyp3rlinx.altervista.org/advisories/NEC-UNIVERGE-WEBPRO-v6.00-PREDICTABLE-SESSIONID-CL... | MISC | hyp3rlinx.altervista.org | Exploit, Third Party Advisory |
| NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| NEC Univerge Sv9100 WebPro 6.00.00 Predictable Session ID / Cleartext Passwords ≈ Packet Storm | MISC | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.