Skip to content

Commit 09e2623

Browse files
thiagoai1adonm
andauthored
Sophos Web Appliance Vulnerabilities (#412)
* Compromised Microsoft Key advisory * CISA Releases IDOR Vulnerability joint Advisory - 20230801001 * Sophos Web Appliance Vulnerabilities * Update 20231117002-Sophos-Web-Appliance-Vulnerability.md --------- Co-authored-by: Adon Metcalfe <[email protected]>
1 parent 8da63c7 commit 09e2623

File tree

1 file changed

+33
-0
lines changed

1 file changed

+33
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
# Sophos Web Appliance Command Injection Vulnerability - 20231117002
2+
3+
## Overview
4+
5+
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
6+
7+
## What is the vulnerability?
8+
9+
[**CVE-2023-1671**](https://nvd.nist.gov/vuln/detail/CVE-2023-1671) - CVSS v3 Base Score: ***9.8***
10+
11+
## What is vulnerable?
12+
13+
Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
14+
15+
The vulnerability affects the following products:
16+
17+
- Sophos Web Appliance Appliance older than version 4.3.10.4
18+
19+
## What has been observed?
20+
21+
There is evidence of active exploitation and the vulnerability was added to the [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) on **2023-11-16**.
22+
23+
## Recommendation
24+
25+
The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hours* (refer [Patch Management](../guidelines/patch-management.md)):
26+
27+
- [Sophos Web Appliance 4.3.10.4 Resolves Security Vulnerabilities](https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce)
28+
29+
## Additional References
30+
31+
- [Sophos Web Appliance 4.3.10.4 Resolves Security Vulnerabilities](https://www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce)
32+
- [Sophos Web Appliance 4.3.10.4 Command Injection](https://packetstormsecurity.com/files/172016/Sophos-Web-Appliance-4.3.10.4-Command-Injection.html)
33+

0 commit comments

Comments
 (0)