← Vulnerability feed

Vulnerability record · CVE-2014-4976 · published 16 July 2014

CVE-2014-4976: Sonicwall scrutinizer permissions and access controls vulnerability

Sonicwall · Scrutinizer

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.

5.5 CVSS 2.0 Medium EPSS 2.7% · top 14.4% CWE-264 · Permissions and access controls
5.5CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change password request to cgi-bin/admin.cgi.

AV:N/AC:L/Au:S/C:N/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-4976 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2012-2627Sonicwall scrutinizer vulnerabilityd4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…EPSS 5.7%7.5CVE-2012-3951Plixer Scrutinizer default admin password enables SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and…EPSS 52%analysed6.5CVE-2014-4977Dell SonicWall Scrutinizer SQL injection in admin and exporter endpointsDell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such…EPSS 75%analysed6.5CVE-2012-2962Plixer Scrutinizer statusFilter.php SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is p…EPSS 67%analysed5.0CVE-2012-2626Sonicwall scrutinizer improper authentication vulnerabilitycgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…EPSS 44%4.3CVE-2012-3848Sonicwall scrutinizer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remo…EPSS 2.5%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2014-4976), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.