Vulnerability record · CVE-2012-4957 · published 18 November 2012
CVE-2012-4957: Novell File Reporter NFRAgent.exe path traversal arbitrary file read
Novell · File Reporter
NFRAgent.exe in Novell File Reporter 1.0.2 contains an absolute path traversal flaw (CWE-22). A remote attacker can send a /FSF/CMD request with a full pathname in the PATH element of an SRS record to read arbitrary files on the host. Because the exposed agent service reads files outside its intended directory, sensitive configuration and credential material may be disclosed.
Description
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.
AV:N/AC:L/Au:N/C:C/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read with a very high EPSS score, though no confirmed in-the-wild exploitation or KEV listing is present.
What it is
NFRAgent.exe in Novell File Reporter 1.0.2 contains an absolute path traversal flaw (CWE-22). A remote attacker can send a /FSF/CMD request with a full pathname in the PATH element of an SRS record to read arbitrary files on the host. Because the exposed agent service reads files outside its intended directory, sensitive configuration and credential material may be disclosed.
Impact
An unauthenticated remote attacker gains read access to arbitrary files on the system running NFRAgent.exe, limited to confidentiality loss with no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network via the NFRAgent.exe service handling /FSF/CMD requests; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is 0.6762 (99.3rd percentile), indicating a high modeled likelihood of exploitation; reference tags are limited to a US Government Resource and a Rapid7 blog post, with no explicit exploit tag.
What to do
- Apply the vendor fix or upgrade Novell File Reporter past 1.0.2 if a patched release is available; the record does not name a fixed version.
- Restrict network access to the NFRAgent.exe service so only trusted management hosts can reach it.
- Run the agent under a low-privilege account and limit its filesystem read permissions to required directories.
- Monitor CERT/CC advisory VU#273371 for updated vendor guidance.
Detection
- Inspect NFRAgent.exe /FSF/CMD request logs for PATH elements containing absolute paths or traversal sequences such as ../.
- Alert on file read activity by the NFRAgent service account outside its expected data directories.
- Baseline normal SRS record traffic and flag anomalous or unexpected file path values.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4957 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4957), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.