Vulnerability record · CVE-2012-3951 · published 31 July 2012
CVE-2012-3951: Plixer Scrutinizer default admin password enables SQL injection
Sonicwall · Scrutinizer
Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and scrutremote accounts. Because those credentials are known and unchanged by default, a remote attacker can authenticate to the MySQL component and execute arbitrary SQL commands over a TCP session.
Description
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityDefault credentials give unauthenticated remote attackers a direct path to arbitrary SQL execution, and public exploit detail plus a very high EPSS score raise the likelihood of attempted exploitation.
What it is
Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and scrutremote accounts. Because those credentials are known and unchanged by default, a remote attacker can authenticate to the MySQL component and execute arbitrary SQL commands over a TCP session.
Impact
An attacker gains authenticated access to the MySQL component and can run arbitrary SQL, allowing data theft or modification and potential further compromise of the Scrutinizer host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reachable over the network via a TCP session to the MySQL component; no user interaction is required. The only barrier is authentication, which is defeated by the default admin password.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is 0.51995 (98.9th percentile), and the Trustwave advisory reference is tagged as an exploit, indicating public exploit detail exists.
What to do
- Upgrade to Plixer Scrutinizer 9.5.2 or later, which the vendor release notes address.
- Immediately change the default passwords for the scrutinizer and scrutremote accounts.
- Restrict network access to the MySQL component so only trusted management hosts can reach it.
- Audit for any other default or shared credentials in the deployment and rotate them.
Detection
- Monitor MySQL authentication logs for successful logins to the scrutinizer or scrutremote accounts, especially from unexpected source addresses.
- Alert on SQL statements containing UNION, stacked queries or other injection patterns arriving from Scrutinizer application hosts.
- Baseline normal connection sources to the MySQL component and flag new or anomalous clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.html | Third Party Advisory |
| https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txt | ExploitThird Party Advisory |
| http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.html | Third Party Advisory |
| https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txt | ExploitThird Party Advisory |
Track CVE-2012-3951 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3951), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.