6.5
CVE-2012-1258
- EPSS 4.78%
- Veröffentlicht 09.01.2020 20:15:09
- Zuletzt bearbeitet 21.11.2024 01:36:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plixer ≫ Scrutinizer Netflow & Sflow Analyzer Version < 9.0.1.19899
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.78% | 0.884 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.