CVE-2012-1258: Plixer Scrutinizer Netflow & Sflow Analyzer

Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.

cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate user permissions, which allow remote attackers to add user accounts with administrator privileges via the newuser, pwd, and selectedUserGroup parameters.

Affected products

  • Plixer Scrutinizer Netflow & Sflow Analyzer: before 9.0.1.19899 (fixed in 9.0.1.19899)

Published 2020-01-09. Last modified 2026-06-16.