CVE-2012-3951
Plixer Scrutinizer NetFlow and sFlow Analyzer 9 - Default MySQL Credential
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
El componente MySQL en Plixer Scrutinizer (también conocido como Dell SonicWALL Scrutinizer) v9.0.1.19899 y anteiores tiene una contraseña por defecto para el admin en (1) scrutinizer y (2) cuentas scrutremote, lo que permite a atacantes remotos ejecutar comandos SQL a través de una sesión TCP.
Scrutinizer NetFlow and sFlow Analyzer versions 9.0.1 and below suffer from bypass, cross site scripting, and remote file upload vulnerabilities. It also has undocumented MySQL admin users.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-07-10 CVE Reserved
- 2012-07-29 CVE Published
- 2012-08-08 First Exploit
- 2024-09-17 CVE Updated
- 2024-10-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.html | Third Party Advisory | |
http://web.archive.org/web/20140722224651/http://secunia.com/advisories/50074 |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/20355 | 2012-08-08 | |
https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txt | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sonicwall Search vendor "Sonicwall" | Scrutinizer Search vendor "Sonicwall" for product "Scrutinizer" | <= 9.0.1.19899 Search vendor "Sonicwall" for product "Scrutinizer" and version " <= 9.0.1.19899" | - |
Affected
|