CVE-2012-3951
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 52.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 52.00% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sonicwall/scrutinizer
- Source
- cve@mitre.org
References
- http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.htmlThird Party Advisory
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txtExploit, Third Party Advisory
- http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.htmlThird Party Advisory
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.