Netsweeper operates a web-filtering and content-control appliance deployed across enterprise and service-provider networks, where its centralized position creates a high-value target for authentication and input-handling attacks. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, concentrated in the core Netsweeper appliance through recurring weakness classes including improper authentication, cross-site scripting, SQL injection, cross-site request forgery, and exposure of sensitive information that are characteristic of web-facing administrative interfaces. Defenders should prioritize patching this vendor's disclosures and restrict network access to the appliance management layer; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netsweeper over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-13167CRITICAL Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-suppli | May 19, 2020 | 9.8 | 88 | NO | YES |
CVE-2014-9618CRITICAL The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbi | Sep 19, 2017 | 9.8 | 80 | NO | YES |
CVE-2014-9614CRITICAL The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to w | Feb 19, 2020 | 9.8 | 76 | NO | YES |
CVE-2014-9613CRITICAL Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verifica | Feb 19, 2020 | 9.8 | 41 | NO | YES |
CVE-2014-9611CRITICAL Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php. | Sep 19, 2017 | 9.8 | 40 | NO | YES |
CVE-2012-3859HIGH Unspecified vulnerability in the WebAdmin Portal in Netsweeper has unknown impact and attack vectors, a different vulnerability than CVE-2012-2446 and CVE-2012-2447. | Jul 9, 2012 | 10.0 | 40 | NO | YES |
CVE-2014-9612CRITICAL SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary | Feb 19, 2020 | 9.8 | 36 | NO | YES |
CVE-2014-9605HIGH WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the | Sep 4, 2015 | 9.4 | 34 | NO | YES |
CVE-2014-9617MEDIUM Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing att | Feb 19, 2020 | 6.1 | 33 | NO | YES |
CVE-2014-9619HIGH Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authent | Sep 19, 2017 | 7.2 | 30 | NO | YES |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netsweeper.
Media articles that mention a CVE ID that affects a product developed by Netsweeper — matched by CVE ID, not by vendor name.