CVE-2012-3951

UnknownEPSS 52.93%

Last modified

CVE-2012-3951 is a vulnerability of currently unknown severity. The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.. EPSS estimates a 52.93% chance of exploitation in the next 30 days.

Description

The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.

Metrics

EPSS Probability
52.93%

98.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SonicwallScrutinizer<= 9.0.1.19899

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-3951?
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
How severe is CVE-2012-3951?
Severity scoring for CVE-2012-3951 is pending analysis. The EPSS model estimates a 52.93% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3951?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-3951?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST