CVE-2012-2627
d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrite arbitrary files in %PROGRAMFILES%\Scrutinizer\snmp\mibs\ via a multipart/form-data POST request.
- CVSS 2.0
- 9.4 HIGHAV:N/AC:L/Au:N/C:N/I:C/A:C
- EPSS
- 5.73% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- sonicwall/scrutinizer
- Source
- cve@mitre.org
References
- http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.htmlBroken Link
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txtThird Party Advisory
- http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.htmlBroken Link
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txtThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.