CVE-2012-2577 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 10.2% (pctl 96)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 10.21% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-08-12 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| solarwinds | orion network performance monitor |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SolarWinds Orion Network Performance Monitor 10.2.2 - Multiple Vulnerabilities | 2012-07-21 |
References
- http://secunia.com/advisories/50004
- http://www.kb.cert.org/vuls/id/174119
- http://www.securityfocus.com/bid/54624
- http://www.solarwinds.com/documentation/Orion/docs/ReleaseNotes/releaseNotes.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77147
- http://secunia.com/advisories/50004
- http://www.kb.cert.org/vuls/id/174119
- http://www.securityfocus.com/bid/54624
- http://www.solarwinds.com/documentation/Orion/docs/ReleaseNotes/releaseNotes.htm
- https://exchange.xforce.ibmcloud.com/vulnerabilities/77147
→ the Explorer · watch your stack · NVD