Vulnerability record · CVE-2012-4958 · published 18 November 2012
CVE-2012-4958: Novell File Reporter NFRAgent.exe directory traversal file read
Novell · File Reporter
NFRAgent.exe in Novell File Reporter 1.0.2 mishandles a 126 /FSF/CMD request containing a .. (dot dot) sequence in the FILE element of an FSFUI record, allowing path traversal. A remote, unauthenticated attacker can read arbitrary files on the host, which matters because the agent typically runs with elevated privileges and exposes configuration and credential material.
Description
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
AV:N/AC:L/Au:N/C:C/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read with a very high EPSS score and public exploit tooling, though no KEV listing or ransomware use is documented.
What it is
NFRAgent.exe in Novell File Reporter 1.0.2 mishandles a 126 /FSF/CMD request containing a .. (dot dot) sequence in the FILE element of an FSFUI record, allowing path traversal. A remote, unauthenticated attacker can read arbitrary files on the host, which matters because the agent typically runs with elevated privileges and exposes configuration and credential material.
Impact
An attacker gains read access to arbitrary files on the system, limited to confidentiality loss with no integrity or availability impact per the CVSS vector. Exposed files could include agent configuration and stored credentials usable for further access.
Attack surface
Reached over the network via a crafted 126 /FSF/CMD request to the NFRAgent service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is very high (0.735 probability, 99.4th percentile) and a Rapid7 Metasploit blog reference suggests public tooling exists.
What to do
- Apply the vendor fix or upgrade Novell File Reporter beyond the affected 1.0.2 release; no patched version is stated in this record, so confirm with the vendor.
- Restrict network access to the NFRAgent service (TCP port used by /FSF/CMD) to trusted management hosts only.
- Run the agent under a least-privilege account so arbitrary file reads expose minimal sensitive data.
- Monitor CERT/CC advisory VU#273371 and vendor channels for updated guidance.
Detection
- Inspect NFRAgent logs and network traffic for 126 /FSF/CMD requests containing .. sequences in FILE elements.
- Alert on FSFUI records with traversal patterns or absolute paths in the FILE field.
- Baseline and monitor file access by the NFRAgent process for reads outside expected report directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4958 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4958), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.