VulnerabilityModified
CVE-2012-1828
The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowledge of a hidden function, as demonstrated by the…
MEDIUM 6.5EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to perform administrative actions by leveraging knowledge of a hidden function, as demonstrated by the password-change function.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- efstechnology/autoform pdm archive
- Source
- cret@cert.org
References
- http://secunia.com/advisories/49335
- http://www.kb.cert.org/vuls/id/773035US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8RQL83US Government Resource
- http://www.securityfocus.com/bid/53716
- http://secunia.com/advisories/49335
- http://www.kb.cert.org/vuls/id/773035US Government Resource
- http://www.kb.cert.org/vuls/id/MAPG-8RQL83US Government Resource
- http://www.securityfocus.com/bid/53716
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.