CVE-2014-9610: Netsweeper

Medium severity, CVSS 5.3. EPSS: 3.7% chance of exploitation in the next 30 days.

Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user/quarantine_disable.php.

Affected products

  • Netsweeper Netsweeper: up to and including 3.1.9; version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; …

Published 2017-09-19. Last modified 2026-06-17.