9
CVSSv2

CVE-2009-2344

Published: 07/07/2009 Updated: 10/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor prior to 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.

Vulnerable Product Search on Vulmon Subscribe to Product

sourcefire 3d sensor 4.8

sourcefire 3d sensor 4.8.0.4

sourcefire defense center 4.8

sourcefire defense center 4.8.0.3

sourcefire defense center

sourcefire 3d sensor 4.8.0.3

sourcefire defense center 4.8.0.4

sourcefire 3d sensor

Exploits

Affected product ---------------- Sourcefire 3D Sensor and Defense Center 48x Tested on 4803 and 4804, 3D Sensor 2500 & DC 1000 All 48x releases, up to and including 481, confirmed vulnerable by sourcefire Vulnerability details --------------------- A privilege escalation vulnerability found in the Sensor and the DC web based ...