CVE-2009-2344
Published Jul 7, 2009
Last updated 6 years ago
Overview
- Description
- The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9
- Impact score
- 10
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:sourcefire:3d_sensor:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F78FF4A-7E52-48AC-BA6C-134A2CF16E4C", "versionEndIncluding": "4.8.1" }, { "criteria": "cpe:2.3:h:sourcefire:3d_sensor:4.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B8C912A2-516B-4812-9202-015A181D2768" }, { "criteria": "cpe:2.3:h:sourcefire:3d_sensor:4.8.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8573E9A-5F6A-4A31-AC29-47A5021AECF0" }, { "criteria": "cpe:2.3:h:sourcefire:3d_sensor:4.8.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "997B953B-7DCC-4707-8BEE-95218461864D" }, { "criteria": "cpe:2.3:h:sourcefire:defense_center:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2902AF6-3F68-4FC7-8012-64BD406367FA", "versionEndIncluding": "4.8.1" }, { "criteria": "cpe:2.3:h:sourcefire:defense_center:4.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "981AB37C-4308-4339-A024-583CB09D9703" }, { "criteria": "cpe:2.3:h:sourcefire:defense_center:4.8.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FC3E2566-A460-4D7E-9991-B026B407F600" }, { "criteria": "cpe:2.3:h:sourcefire:defense_center:4.8.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64DBAB25-4691-4225-9AA4-66E93F31A93B" } ], "operator": "OR" } ] } ]