Vulnerability Description
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Scrutinizer | <= 9.0.1.19899 |
Related Weaknesses (CWE)
References
- http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.htmlThird Party Advisory
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txtExploitThird Party Advisory
- http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.htmlThird Party Advisory
- https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txtExploitThird Party Advisory
FAQ
What is CVE-2012-3951?
CVE-2012-3951 is a vulnerability with a CVSS score of 7.5 (HIGH). The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows re...
How severe is CVE-2012-3951?
CVE-2012-3951 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-3951?
Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Scrutinizer.