CVE-2014-9353

CRITICAL

NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.

Affects 1 product across 1 vendor.

BCS7.6
CVSS 2.010.0
EPSS2.9%
Percentile86th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2015. A critical vulnerability affects Netapp systems (CVE-2014-9353). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2015-GLOBAL-264064-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2014-9353?
This vulnerability was disclosed in 2015. A critical vulnerability affects Netapp systems (CVE-2014-9353). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2014-9353?
CVE-2014-9353 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 2.9%.
Is CVE-2014-9353 actively exploited?
No confirmed active exploitation of CVE-2014-9353 as of 2026-05-30.
How do I remediate CVE-2014-9353?
Priority: MEDIUM. Advisory: https://kb.netapp.com/support/index?page=content&id=9010020 PSIRT: [email protected]
What systems are affected by CVE-2014-9353?
CVE-2014-9353 affects: Netapp.
Vulnerability Details
CVE IDCVE-2014-9353
BSIDBS-2015-GLOBAL-264064-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2015-02-06
Last Modified2026-05-06
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Netapp Oncommand Balance
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 4187 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash91b4e8560286616698f5e4a95ccf16e52aef244a35ca9283bd5d23adc35c1a4630fa9d797c3b5667093950d8391b0385243f8b4c49452b3858c1bf8c8ad72488
Related CVEs affecting Netapp
CVE-2008-3349 10.0 Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp ... CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2015-3292 10.0 The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x ... CVE-2020-4561 10.0 IBM Cognos Analytics 11.0 and 11.1 DQM API allows submitting of all control r... CVE-2021-21345 9.9 XStream is a Java library to serialize objects to XML and back again. In XStr...
View all Netapp CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →