Sophos
Sophos WEB Appliance: vulnerabilidades y CVE
Sophos WEB Appliance tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1671 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 abr 2023 | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2009-20011 | Crítica (10) | 1.4% | — | 30 ago 2025 | ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The… |
| CVE-2023-33336 | Media (4.8) | 0.58% | — | 30 jun 2023 | Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes. |
| CVE-2023-1671 | Crítica (9.8) | 100% | ⚠ Explotación activa | 4 abr 2023 | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code. |
| CVE-2022-4934 | Alta (7.2) | 1.8% | — | 4 abr 2023 | A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code. |
| CVE-2020-36692 | Media (5.4) | 0.57% | — | 4 abr 2023 | A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually… |
| CVE-2017-9523 | Media (6.1) | 1.2% | — | 9 jun 2017 | The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342. |
| CVE-2017-6412 | Alta (8.1) | 7.5% | — | 30 mar 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. |
| CVE-2017-6184 | Media (4.7) | 2.5% | — | 30 mar 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303. |
| CVE-2017-6183 | Alta (7.2) | 3.2% | — | 30 mar 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314. |
| CVE-2017-6182 | Crítica (9.8) | 17% | — | 30 mar 2017 | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304. |
| CVE-2016-9554 | Alta (7.2) | 25% | — | 28 ene 2017 | The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in… |
| CVE-2016-9553 | Alta (7.2) | 19% | — | 28 ene 2017 | The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php… |
| CVE-2014-2850 | Alta (8.5) | 58% | — | 11 abr 2014 | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter. |
| CVE-2014-2849 | Alta (8.5) | 60% | — | 11 abr 2014 | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request. |
| CVE-2013-2643 | Media (4.3) | 4.5% | — | 18 mar 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg… |
| CVE-2013-2642 | Alta (9.3) | 6.9% | — | 18 mar 2014 | Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a… |
| CVE-2013-2641 | Media (5) | 71% | — | 18 mar 2014 | Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter. |
| CVE-2013-4984 | Alta (7.2) | 8.1% | — | 10 sept 2013 | The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Sophos
Sophos Anti-virus · 36Anti-virus · 12Firewall Firmware · 10Sophos Puremessage Anti-virus · 9XG Firewall Firmware · 9Unified Threat Management Software · 9Safeguard Easy Device Encryption Client · 8Sfos · 8Sophos Small Business Suite · 8Safeguard LAN Crypt Client · 7Safeguard Enterprise Client · 7Unified Threat Management · 6