Vulnerability record · CVE-2012-4959 · published 18 November 2012
CVE-2012-4959: Novell File Reporter NFRAgent.exe path traversal allows remote file upload and execution
Novell · File Reporter
NFRAgent.exe in Novell File Reporter 1.0.2 is vulnerable to directory traversal. A remote attacker can send a crafted 130 /FSF/CMD request containing a .. (dot dot) sequence in the FILE element of an FSFUI record to write and execute files on the target. This gives unauthenticated code execution on the affected service.
Description
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability makes this an urgent patching priority.
What it is
NFRAgent.exe in Novell File Reporter 1.0.2 is vulnerable to directory traversal. A remote attacker can send a crafted 130 /FSF/CMD request containing a .. (dot dot) sequence in the FILE element of an FSFUI record to write and execute files on the target. This gives unauthenticated code execution on the affected service.
Impact
An attacker can upload and execute arbitrary files on the host running NFRAgent.exe, leading to full compromise of the service account and the underlying system. With no authentication required, this is a complete loss of confidentiality, integrity and availability.
Attack surface
The flaw is reached over the network through the NFRAgent.exe service handling 130 /FSF/CMD requests. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.71194 (99.377th percentile), indicating a high likelihood of exploitation activity. A public Rapid7 Metasploit blog reference exists, suggesting exploit tooling is available.
What to do
- Apply the vendor patch or upgrade Novell File Reporter beyond the affected 1.0.2 release as soon as possible.
- Restrict network access to the NFRAgent.exe service (default port not stated in the record) to trusted management hosts only.
- Run the NFRAgent service under a low-privilege account with no write access to executable directories.
- Monitor and block traversal patterns such as '..' in FSFUI FILE elements at the network or application layer.
- If the product is no longer supported, isolate or decommission the affected host.
Detection
- Inspect NFRAgent logs and network traffic for 130 /FSF/CMD requests containing '..' in FILE elements.
- Alert on unexpected file creation or modification in directories writable by the NFRAgent service account.
- Monitor for child processes spawned by NFRAgent.exe, especially command shells or script interpreters.
- Use file integrity monitoring on directories where uploaded files could be executed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-4959 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-4959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.