SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-1258

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and…

MEDIUM 6.5EPSS 3.33%

Does this matter?

Lower severity and a low EPSS score (3.33%). Track it; it rarely justifies an emergency change on its own.

Description

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS
3.33% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
plixer/scrutinizer netflow \& sflow analyzer
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.