CVE-2014-2509: Emc Smarts Network Configuration Manager

Medium severity, CVSS 5.4. EPSS: 1.6% chance of exploitation in the next 30 days.

Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie.

Affected products

  • Emc Smarts Network Configuration Manager: up to and including 9.2; version 9.1 only

Published 2014-07-01. Last modified 2026-06-17.