CVE-2012-2577
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 10.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- solarwinds/orion network performance monitor
- Source
- cret@cert.org
References
- http://secunia.com/advisories/50004Vendor Advisory
- http://www.kb.cert.org/vuls/id/174119US Government Resource
- http://www.securityfocus.com/bid/54624Exploit
- http://www.solarwinds.com/documentation/Orion/docs/ReleaseNotes/releaseNotes.htmVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77147
- http://secunia.com/advisories/50004Vendor Advisory
- http://www.kb.cert.org/vuls/id/174119US Government Resource
- http://www.securityfocus.com/bid/54624Exploit
- http://www.solarwinds.com/documentation/Orion/docs/ReleaseNotes/releaseNotes.htmVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77147
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.