vendor:
Netsweeper
by:
Anastasios Monachos
9,8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: Netsweeper
Affected Version From: 4.0.8
Affected Version To: 4.0.8
Patch Exists: Yes
Related CWE: CVE-2014-9618
CPE: a:netsweeper:netsweeper
Metasploit:
N/A
Other Scripts:
N/A
Tags: cve2014,netsweeper,auth-bypass,packetstorm,edb,cve
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'vendor': 'netsweeper', 'product': 'netsweeper'}
Platforms Tested: None
2014
Netsweeper 4.0.8 – Authentication Bypass (New Profile Creation)
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via a showdeny action to the default URL.
Mitigation:
Upgrade to latest version.