CVE-2012-2626
medium · 5cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.
5
CVSS
44.5%
EPSS (exploit prob.)
99th
EPSS percentile
2012-07-31
Published
AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sonicwall | scrutinizer | < 9.5.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-2626