PT-2020-7180 · Plixer International · Scrutinizer Netflow & Sflow Analyzer
Tanya Secker
·
Published
2020-01-09
·
Updated
2020-01-22
·
CVE-2012-1258
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Plixer International Scrutinizer NetFlow & sFlow Analyzer versions prior to 9.0.1.19899
Description
The issue concerns a lack of user permission validation in the cgi-bin/userprefs.cgi component. This allows remote attackers to create new user accounts with administrator privileges by exploiting the
newuser, pwd, and selectedUserGroup parameters.Recommendations
For versions prior to 9.0.1.19899, update to version 9.0.1.19899 or later to resolve the issue. As a temporary workaround, consider restricting access to the cgi-bin/userprefs.cgi component to prevent unauthorized account creation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scrutinizer Netflow & Sflow Analyzer