You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
# Sophos Web Appliance Command Injection Vulnerability - 20231117002
2
+
3
+
## Overview
4
+
5
+
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
6
+
7
+
## What is the vulnerability?
8
+
9
+
[**CVE-2023-1671**](https://nvd.nist.gov/vuln/detail/CVE-2023-1671) - CVSS v3 Base Score: ***9.8***
10
+
11
+
## What is vulnerable?
12
+
13
+
Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
14
+
15
+
The vulnerability affects the following products:
16
+
17
+
- Sophos Web Appliance Appliance older than version 4.3.10.4
18
+
19
+
## What has been observed?
20
+
21
+
There is evidence of active exploitation and the vulnerability was added to the [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) on **2023-11-16**.
22
+
23
+
## Recommendation
24
+
25
+
The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours* (refer [Patch Management](../guidelines/patch-management.md)):
26
+
27
+
-[Sophos Web Appliance 4.3.10.4 Resolves Security Vulnerabilities](https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce)
28
+
29
+
## Additional References
30
+
31
+
-[Sophos Web Appliance 4.3.10.4 Resolves Security Vulnerabilities](https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce)
32
+
-[Sophos Web Appliance 4.3.10.4 Command Injection](https://packetstormsecurity.com/files/172016/Sophos-Web-Appliance-4.3.10.4-Command-Injection.html)
0 commit comments