CVE-2012-2962 describes a SQL injection vulnerability in Plixer Scrutinizer (also known as Dell SonicWALL Scrutinizer) versions prior to 9.5.2, specifically within the d4d/statusFilter.php component. This flaw allows remote authenticated attackers to execute arbitrary SQL commands by manipulating the 'q' parameter. The vulnerability carries a CVSS score of 6.5, indicating a medium severity. It requires authentication (Au:S) but can be exploited over the network (AV:N) with low attack complexity (AC:L), potentially leading to partial compromise of confidentiality, integrity, and availability (C:P/I:P/A:P). While not listed on the CISA KEV catalog, exploit intelligence shows a Metasploit module and ExploitDB entries exist, confirming public exploit code availability. Despite this, community discussion and media coverage for this CVE are minimal, suggesting it has not garnered significant public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.5.2CPE matchmatch criteria | cpe:2.3:a:sonicwall:scrutinizer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.