CVE-2014-9611: Netsweeper

Critical severity, CVSS 9.8. EPSS: 12.7% chance of exploitation in the next 30 days.

Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php.

Affected products

Published 2017-09-19. Last modified 2026-06-17.