First published: Tue Jul 31 2012(Updated: )
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL Scrutinizer | <9.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2626 has been classified as a high severity vulnerability due to its potential exploitation allowing unauthorized administrative access.
CVE-2012-2626 affects Plixer Scrutinizer versions prior to 9.5.0.
To mitigate the risk of CVE-2012-2626, upgrade your Plixer Scrutinizer to version 9.5.0 or later.
CVE-2012-2626 allows remote attackers to add administrative accounts without proper authentication.
No, the affected versions of Plixer Scrutinizer do not require token authentication, making them vulnerable.