Vulnerability record · CVE-2014-9614 · published 19 February 2020
CVE-2014-9614: Netsweeper Web Panel hard-coded branding account password
Netsweeper · Netsweeper
The Netsweeper Web Panel before 4.0.5 ships with a default password of 'branding' for the branding account. Anyone who can reach the webadmin/ interface can log in with these known credentials and gain administrative access to the panel.
Description
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityA remotely reachable, unauthenticated default credential with a CVSS score of 9.8 and very high EPSS probability gives attackers full panel access with minimal effort.
What it is
The Netsweeper Web Panel before 4.0.5 ships with a default password of 'branding' for the branding account. Anyone who can reach the webadmin/ interface can log in with these known credentials and gain administrative access to the panel.
Impact
An attacker gains authenticated access to the Netsweeper Web Panel with the privileges of the branding account, which the CVSS vector rates as high for confidentiality, integrity and availability.
Attack surface
Reachable remotely over the network via a request to webadmin/ with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is 0.687 (99.3rd percentile), indicating a high modeled likelihood of exploitation, and the only references are third-party advisories with no exploit tag.
What to do
- Upgrade Netsweeper to 4.0.5 or later, which removes the default branding password.
- If upgrade is not immediate, change the branding account password and disable or rename the account if it is unused.
- Restrict network access to the webadmin/ interface to trusted management networks only.
- Audit for any other default or hard-coded accounts in the Web Panel and rotate their credentials.
Detection
- Search Web Panel authentication logs for successful logins to the branding account, especially from unexpected source IPs.
- Alert on any authentication to webadmin/ using the password 'branding' or other known default credentials.
- Monitor for first-time or anomalous access to the webadmin/ path from external or non-management networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/133034/Netsweeper-Bypass-XSS-Redirection-SQL-Injection-Execution.html | Third Party AdvisoryVDB Entry |
Track CVE-2014-9614 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-9614), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.