Remote Password Change Vulnerability in Dell SonicWall Scrutinizer
CVE-2014-4976
Currently unrated
What is CVE-2014-4976?
Dell SonicWall Scrutinizer version 11.0.1 is susceptible to an issue where remote authenticated users can exploit a flaw in the password change process. By manipulating the user ID within the 'savePrefs' parameter during a request to 'cgi-bin/admin.cgi', an attacker can change user passwords without proper authorization. This oversight can compromise user accounts, leading to unauthorized access and potential abuse of the network system.