Trustwave's 2024 Retail Report Series Highlights Alarming E-Commerce Threats and Growing Fraud Against Retailers. Learn More
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
Trustwave's 2024 Retail Report Series Highlights Alarming E-Commerce Threats and Growing Fraud Against Retailers. Learn More
The SpiderLabs team at Trustwave published a new advisory today, which details four vulnerabilities in Scrutinizer NetFlow & sFlow Analyzer by Plixer International. Scrutinizer NetFlow & sFlow Analyzer is a product used for network analysis to monitor the overall health of a network and reports statistics, such as which hosts, applications and protocols are consuming network bandwidth. These findings include a http authentication bypass vulnerability, arbitrary file upload vulnerability, multiple cross-site scripting vulnerabilities, and undocumented default MySQL user accounts.
For those who have been following the SpiderLabs Anterior blog, Trustwave previously published an advisory for Scrutinizer NetFlow & sFlow Analyzer ( TWSL2012-008 ) in April containing an http authentication bypass vulnerability discovered by Tanya Secker who is a managing consultant for Trustwave SpiderLabs. Based on this finding, Mario Ceballos of the Metasploit Project reached out to us about finding a similar vulnerability that allows bypassing the web application authentication. Mario also reached out to us about detecting security issues with the upload functionality as well. A special thanks to Mario Ceballos for making these discoveries!
Additionally, Jonathan Claudius of Trustwave SpiderLabs discovered security issues with the software having undocumented default MySQL user accounts, and parameters that need to be sanitized for XSS. Plixer International confirmed these findings as well as fixes these issues in version 9.5.0.
As an added note, Trustwave SpiderLabs has deployed protections for these findings in TrustKeeper scanning solution. Trustwave customers using the TrustKeeper Scan Engine will "auto-magically" receive this update.
Trustwave is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.
Copyright © 2024 Trustwave Holdings, Inc. All rights reserved.