HIGH · 9.4

CVE-2014-9605

WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the ...

Vulnerability Description

WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the filters on the server via a ' (single quote) character in the login and password parameters to webupgrade/webupgrade.php. NOTE: this was originally reported as an SQL injection vulnerability, but this may be inaccurate.

CVSS Score

9.4

HIGH

AV:N/AC:L/Au:N/C:C/I:N/A:C
Confidentiality
COMPLETE
Integrity
NONE
Availability
COMPLETE

Affected Products

VendorProductVersions
NetsweeperNetsweeper>= 3.1.0, < 3.1.10

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9605?

CVE-2014-9605 is a vulnerability with a CVSS score of 9.4 (HIGH). WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the ...

How severe is CVE-2014-9605?

CVE-2014-9605 has been rated HIGH with a CVSS base score of 9.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9605?

Check the references section above for vendor advisories and patch information. Affected products include: Netsweeper Netsweeper.