5
CVSSv2

CVE-2012-2626

Published: 31/07/2012 Updated: 08/03/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) prior to 9.5.0 does not require token authentication, which allows remote malicious users to add administrative accounts via a userprefs action.

Vulnerable Product Search on Vulmon Subscribe to Product

sonicwall scrutinizer

Exploits

source: wwwsecurityfocuscom/bid/54727/info Scrutinizer is prone to an authentication-bypass vulnerability Exploiting this issue may allow an attacker to bypass certain security restrictions and perform unauthorized actions Scrutinizer 950 is vulnerable; other versions may also be affected #Request POST /cgi-bin/admincgi HTTP/11 ...
Scrutinizer NetFlow and sFlow Analyzer versions 901 and below suffer from bypass, cross site scripting, and remote file upload vulnerabilities It also has undocumented MySQL admin users ...