CVE-2018-11741 describes a critical vulnerability in NEC Univerge Sv9100 WebPro 6.00.00 devices, allowing for account information disclosure due to predictable session IDs. This flaw enables unauthorized access to sensitive data through manipulated URIs. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to complete compromise of confidentiality, integrity, and availability. Its high EPSS and FAUCET Risk Score further emphasize its severe potential impact. While not listed on the KEV catalog or experiencing widespread community discussion or media coverage, an exploit for predictable session IDs and cleartext password storage is publicly available on ExploitDB. There is no evidence of active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.00.00CPE matchmatch criteria | cpe:2.3:o:nec:univerge_sv9100_webpro_firmware:6.00.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.