← Vulnerability feed

Vulnerability record · CVE-2014-4977 · published 16 July 2014

CVE-2014-4977: Dell SonicWall Scrutinizer SQL injection in admin and exporter endpoints

Sonicwall · Scrutinizer

Dell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such as selectedUserGroup, user_id, methodDetail and xcNetworkDetail. An authenticated attacker can inject arbitrary SQL, which matters because the affected application holds monitoring and configuration data for the network.

6.5 CVSS 2.0 Medium EPSS 75% · top 0.5% CWE-89 · SQL injection
6.5CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in the methodDetail function, or (4) xcNetworkDetail parameter in the xcNetworkDetail function in d4d/exporters.php.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityPublic exploit code exists and EPSS is near the top percentile, but exploitation requires valid credentials and the CVSS impact is only partial.

What it is

Dell SonicWall Scrutinizer 11.0.1 contains multiple SQL injection flaws in cgi-bin/admin.cgi and d4d/exporters.php, reachable through parameters such as selectedUserGroup, user_id, methodDetail and xcNetworkDetail. An authenticated attacker can inject arbitrary SQL, which matters because the affected application holds monitoring and configuration data for the network.

Impact

An attacker with a valid account can execute arbitrary SQL commands against the Scrutinizer database, enabling data disclosure, modification or deletion and potential further compromise of the host. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

Reached remotely over the network via HTTP requests to the admin CGI and exporter PHP endpoints; the CVSS vector (AV:N/AC:L/Au:S) and description both indicate a valid authenticated session is required, with no user interaction beyond normal authenticated use.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.749 probability, 99.48th percentile) and public references include an Exploit tag plus an Exploit-DB entry, indicating public exploit material exists.

What to do

  • Apply the vendor fix or upgrade Scrutinizer past 11.0.1; if no patch is available, isolate the instance.
  • Restrict network access to the Scrutinizer web interface and cgi-bin/d4d paths to trusted management networks only.
  • Enforce least privilege on Scrutinizer accounts and remove or disable unused accounts, since exploitation requires authentication.
  • Deploy a WAF or input validation rules covering the selectedUserGroup, user_id, methodDetail and xcNetworkDetail parameters.
  • Monitor and rotate database credentials used by the Scrutinizer application.

Detection

  • Review web server and application logs for SQL metacharacters or UNION/boolean patterns in the selectedUserGroup, user_id, methodDetail and xcNetworkDetail parameters.
  • Alert on anomalous requests to cgi-bin/admin.cgi and d4d/exporters.php, especially from unusual source addresses or accounts.
  • Baseline normal Scrutinizer database query volume and flag spikes or unexpected schema/table access.
  • Hunt for post-exploitation activity such as new administrative accounts or modified Scrutinizer configuration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/127429/Dell-Sonicwall-Scrutinizer-11.01-Code-Execution-SQL-Injection.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/137098/Dell-SonicWALL-Scrutinizer-11.01-methodDetail-SQL-Injection.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2014/Jul/44 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/68495 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/94439 Third Party AdvisoryVDB Entry
https://gist.github.com/brandonprry/36b4b8df1cde279a9305 Third Party Advisory
https://gist.github.com/brandonprry/76741d9a0d4f518fe297 ExploitThird Party Advisory
https://www.exploit-db.com/exploits/39836/ Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/127429/Dell-Sonicwall-Scrutinizer-11.01-Code-Execution-SQL-Injection.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/137098/Dell-SonicWALL-Scrutinizer-11.01-methodDetail-SQL-Injection.html Third Party AdvisoryVDB Entry
http://seclists.org/fulldisclosure/2014/Jul/44 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/68495 Third Party AdvisoryVDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/94439 Third Party AdvisoryVDB Entry
https://gist.github.com/brandonprry/36b4b8df1cde279a9305 Third Party Advisory
https://gist.github.com/brandonprry/76741d9a0d4f518fe297 ExploitThird Party Advisory
https://www.exploit-db.com/exploits/39836/ Third Party AdvisoryVDB Entry

Track CVE-2014-4977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2012-2627Sonicwall scrutinizer vulnerabilityd4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…EPSS 5.7%7.5CVE-2012-3951Plixer Scrutinizer default admin password enables SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier ships with a default password of 'admin' for the scrutinizer and…EPSS 52%analysed6.5CVE-2012-2962Plixer Scrutinizer statusFilter.php SQL injectionPlixer Scrutinizer (also branded Dell SonicWALL Scrutinizer) before 9.5.2 contains a SQL injection flaw in d4d/statusFilter.php. The q parameter is p…EPSS 67%analysed5.5CVE-2014-4976Sonicwall scrutinizer permissions and access controls vulnerabilityDell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…EPSS 2.7%5.0CVE-2012-2626Sonicwall scrutinizer improper authentication vulnerabilitycgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…EPSS 44%4.3CVE-2012-3848Sonicwall scrutinizer cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allow remo…EPSS 2.5%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2014-4977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.