← back
CVE-2009-4657

CVE-2009-4657

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 2.2%
from disclosure to weapon0 days
Published on NVDMar 3
1st PoCSep 18
exploitation probability
2.2%top 19% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.