Vulnerability record · CVE-2014-4977 · published 16 July 2014
CVE-2014-4977: Dell SonicWall Scrutinizer SQL injection in admin and exporter endpoints
Sonicwall · Scrutinizer
Dell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such as selectedUserGroup, user_id, methodDetail and xcNetworkDetail. An authenticated attacker can inject arbitrary SQL, which matters because the affected application holds monitoring and configuration data for the network.
Description
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in the methodDetail function, or (4) xcNetworkDetail parameter in the xcNetworkDetail function in d4d/exporters.php.
AV:N/AC:L/Au:S/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is near the top percentile, but exploitation requires valid credentials and the CVSS impact is only partial.
What it is
Dell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such as selectedUserGroup, user_id, methodDetail and xcNetworkDetail. An authenticated attacker can inject arbitrary SQL, which matters because the affected application holds monitoring and configuration data for the network.
Impact
An attacker with a valid account can execute arbitrary SQL commands against the Scrutinizer database, enabling data disclosure, modification or deletion and potential further compromise of the host. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reached remotely over the network via HTTP requests to the admin CGI and exporter PHP endpoints; the CVSS vector (AV:N/AC:L/Au:S) and description both indicate a valid authenticated session is required, with no user interaction beyond normal authenticated use.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.749 probability, 99.48th percentile) and public references include an Exploit tag plus an Exploit-DB entry, indicating public exploit material exists.
What to do
- Apply the vendor fix or upgrade Scrutinizer past 11.0.1; if no patch is available, isolate the instance.
- Restrict network access to the Scrutinizer web interface and cgi-bin/d4d paths to trusted management networks only.
- Enforce least privilege on Scrutinizer accounts and remove or disable unused accounts, since exploitation requires authentication.
- Deploy a WAF or input validation rules covering the selectedUserGroup, user_id, methodDetail and xcNetworkDetail parameters.
- Monitor and rotate database credentials used by the Scrutinizer application.
Detection
- Review web server and application logs for SQL metacharacters or UNION/boolean patterns in the selectedUserGroup, user_id, methodDetail and xcNetworkDetail parameters.
- Alert on anomalous requests to cgi-bin/admin.cgi and d4d/exporters.php, especially from unusual source addresses or accounts.
- Baseline normal Scrutinizer database query volume and flag spikes or unexpected schema/table access.
- Hunt for post-exploitation activity such as new administrative accounts or modified Scrutinizer configuration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-4977 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-4977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.