peter bassill · operator
$ cve CVE-2012-1258 JSON

CVE-2012-1258 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 3.3% (pctl 88)

Patch early

A public exploit exists.

Description

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS3.33% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2020-01-09
Last modified2026-06-16

Affected (1)

VendorProduct
plixerscrutinizer netflow \& sflow analyzer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD