Western Digital My Cloud Home before 3.6.0 and ibi before 3.6.0 allow Session Fixation.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://support.wdc.com/downloads.aspx?g=907&lang=en#downloads | patch vendor advisory |
https://www.westerndigital.com/support/productsecurity/wdc-19013-my-cloud-home-and-ibi-session-invalidation-vulnerability | vendor advisory |