cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) prior to 9.5.0 does not require token authentication, which allows remote malicious users to add administrative accounts via a userprefs action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sonicwall scrutinizer |