PT-2012-4140 · Plixer · Plixer Scrutinizer

Published

2012-07-31

·

Updated

2018-03-08

·

CVE-2012-2626

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) versions prior to 9.5.0
Description The issue concerns the lack of token authentication in the cgi-bin/admin.cgi endpoint of the web console, allowing remote attackers to add administrative accounts via a userprefs action.
Recommendations For versions prior to 9.5.0, update to version 9.5.0 or later to resolve the issue.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2626

Affected Products

Plixer Scrutinizer