9.8
CVSSv3

CVE-2018-11741

Published: 26/12/2018 Updated: 13/09/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nec univerge_sv9100_webpro_firmware 6.00.00

Exploits

NEC Univerge Sv9100 WebPro version 60000 suffers from predictable session identifiers and cleartext password vulnerabilities ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> CVE-2018-11741 / CVE-2018-11742 / NEC Univerge Sv9100 WebPro - 600 / Predictable Session ID / Clear Text Password Stor ...