Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.
References
Configurations
History
No history.
Information
Published : 2014-07-16 14:19
Updated : 2025-04-12 10:46
NVD link : CVE-2014-4976
Mitre link : CVE-2014-4976
CVE.ORG link : CVE-2014-4976
JSON object : View
Products Affected
sonicwall
- scrutinizer
CWE
CWE-264
Permissions, Privileges, and Access Controls