CVE-2012-3951
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 52%
from disclosure to weapon8 days
Published on NVDJul 31
1st PoC+8d
metasploitJul 27
exploitation probability
52%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scrutinizer and (2) scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands via a TCP session.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/20355unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.