Critical severity9.8NVD Advisory· Published Jul 8, 2009· Updated Apr 23, 2026
CVE-2009-2367
CVE-2009-2367
Description
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
Affected products
1- cpe:2.3:o:iomega:storcenter_pro_firmware:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- osvdb.org/55586nvdBroken LinkExploit
- trac.metasploit.com/browser/framework3/trunk/modules/auxiliary/admin/http/iomega_storcenterpro_sessionid.rbnvdBroken LinkExploit
- secunia.com/advisories/35666nvdBroken LinkVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/51539nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.