Iomega StorCentre Pro Network-Attached-Storage contains a flaw that may allow an unauthenticated user to bypass access control and gain access to the administrator account. The issue is due to a flaw in the web application session id generation and can be easily brute forced. This flaw may lead to a loss of confidentiality and integrity.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Uncoordinated Disclosure
Technical
The CGI script /cgi-bin/makecgi-pro generates session_id values which are incremented for every logon/logoff event. The next authenticated session can be guessed by incrementing the session_id value.
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.