HIGH · 9.0

CVE-2009-2344

The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an ed...

Vulnerability Description

The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.

CVSS Score

9.0

HIGH

AV:N/AC:L/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Sourcefire3D Sensor<= 4.8.1
SourcefireDefense Center<= 4.8.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-2344?

CVE-2009-2344 is a vulnerability with a CVSS score of 9.0 (HIGH). The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an ed...

How severe is CVE-2009-2344?

CVE-2009-2344 has been rated HIGH with a CVSS base score of 9.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-2344?

Check the references section above for vendor advisories and patch information. Affected products include: Sourcefire 3D Sensor, Sourcefire Defense Center.