CVE-2009-2367

CRITICAL

Iomega StorCenter Pro - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2367. PoCs published by aushack, including Metasploit module auxiliary/admin/http/iomega_storcenterpro_sessionid.

AI-analyzed exploit summary This Metasploit module exploits a session ID brute-force vulnerability in Iomega StorCenter Pro NAS devices, allowing authentication bypass by incrementally testing session IDs. It sends HTTP requests to check for valid sessions and reports success if a valid session is found.

Description

cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.

Exploits (1)

metasploit WORKING POC
by aushack · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/iomega_storcenterpro_sessionid.rb

This Metasploit module exploits a session ID brute-force vulnerability in Iomega StorCenter Pro NAS devices, allowing authentication bypass by incrementally testing session IDs. It sends HTTP requests to check for valid sessions and reports success if a valid session is found.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Iomega StorCenter Pro NAS
No auth needed
Prerequisites: Network access to the target device
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Broken Link, Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/55586
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35666
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51539

Scores

CVSS v3 9.8
EPSS 0.3233
EPSS Percentile 97.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-338
Status published
Products (1)
iomega/storcenter_pro_firmware
Published Jul 08, 2009
Tracked Since Feb 18, 2026