Plixer.Scrutinizer.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass vulnerability in Plixer Scrutinizer.
The vulnerability is due to a validation error in the application when handling an HTTP request. Via an HTTP request, an unauthenticated remote attacker may be able to exploit this to bypass authentication on vulnerable systems by adding administrative accounts.

affected-products-logoAffected Products

Plixer Scrutinizer version before 9.5.0

Impact logoImpact

Security Bypass: Remote attackers can bypass security features of vulnerable systems by adding administrative accounts without authentication.

recomended-action-logoRecommended Actions

Currently we are not aware any vendor provided patch to address this issue.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-06-28 14.641 Default_action:pass:drop
2019-06-10 14.629