← Vulnerability feed

Vulnerability record · CVE-2012-3951 · published 31 July 2012

CVE-2012-3951: Plixer Scrutinizer default admin password enables SQL injection

Sonicwall · Scrutinizer

Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and scrutremote accounts. Because those credentials are known and unchanged by default, a remote attacker can authenticate to the MySQL component and execute arbitrary SQL commands over a TCP session.

7.5 CVSS 2.0 High EPSS 52% · top 1.1% CWE-89 · SQL injection
7.5CVSS 2.0 base score
52%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityDefault credentials give unauthenticated remote attackers a direct path to arbitrary SQL execution, and public exploit detail plus a very high EPSS score raise the likelihood of attempted exploitation.

What it is

Plixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and scrutremote accounts. Because those credentials are known and unchanged by default, a remote attacker can authenticate to the MySQL component and execute arbitrary SQL commands over a TCP session.

Impact

An attacker gains authenticated access to the MySQL component and can run arbitrary SQL, allowing data theft or modification and potential further compromise of the Scrutinizer host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

Reachable over the network via a TCP session to the MySQL component; no user interaction is required. The only barrier is authentication, which is defeated by the default admin password.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is 0.51995 (98.9th percentile), and the Trustwave advisory reference is tagged as an exploit, indicating public exploit detail exists.

What to do

  • Upgrade to Plixer Scrutinizer 9.5.2 or later, which the vendor release notes address.
  • Immediately change the default passwords for the scrutinizer and scrutremote accounts.
  • Restrict network access to the MySQL component so only trusted management hosts can reach it.
  • Audit for any other default or shared credentials in the deployment and rotate them.

Detection

  • Monitor MySQL authentication logs for successful logins to the scrutinizer or scrutremote accounts, especially from unexpected source addresses.
  • Alert on SQL statements containing UNION, stacked queries or other injection patterns arriving from Scrutinizer application hosts.
  • Baseline normal connection sources to the MySQL component and flag new or anomalous clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3951 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2012-2627Sonicwall scrutinizer vulnerabilityd4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…EPSS 5.7%6.5CVE-2014-4977Dell SonicWall Scrutinizer SQL injection in admin and exporter endpointsDell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such…EPSS 75%analysed6.5CVE-2012-2962Plixer Scrutinizer statusFilter.php SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is p…EPSS 67%analysed5.5CVE-2014-4976Sonicwall scrutinizer permissions and access controls vulnerabilityDell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…EPSS 2.7%5.0CVE-2012-2626Sonicwall scrutinizer improper authentication vulnerabilitycgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…EPSS 44%4.3CVE-2012-3848Sonicwall scrutinizer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remo…EPSS 2.5%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2012-3951), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.