peter bassill · operator
$ cve CVE-2012-2577 JSON

CVE-2012-2577 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 10.2% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS10.21% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2012-08-12
Last modified2026-06-16

Affected (1)

VendorProduct
solarwindsorion network performance monitor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD