Release date:
Updated on:
Affected Systems:
Dell SonicWALL Scrutinizer <9.0.1.19899
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-3951
Dell SonicWALL Scrutinizer is a multi-vendor visual reporting tool for application communication analysis, which measures and solves network performance and usage.
Plixer Scrutinizer (Dell SonicWALL Scrutinizer) 9.0.1.19899 and the MySQL components in earlier versions have the default administrator password of scrutinizer and scrutremote accounts, which allows remote attackers to execute arbitrary SQL commands through TCP sessions.
<* Source: vendor
Link: https://www.trustwave.com/spiderlabs/advisories/TWSL2012-014.txt
Http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Dell
----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.plixer.com/Press-Releases/plixer-releases-9-5-2.html