Skip to main content

Vendor/product archive

sophos / web_appliance CVEs

Beta · best-effort

18 CVEs tagged to sophos / web_appliance4 Critical, 8 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2023-33336

Published Jun 30, 2023

Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1671

Published Apr 4, 2023

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2022-4934

Published Apr 4, 2023

A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.

CVSS 7.2 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2020-36692

Published Apr 4, 2023

A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a mal…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6184

Published Mar 30, 2017

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token para…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6183

Published Mar 30, 2017

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote comma…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6182

Published Mar 30, 2017

In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9554

Published Jan 28, 2017

The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9553

Published Jan 28, 2017

The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2643

Published Mar 18, 2014

Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2013-4984

Published Sep 10, 2013

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metachar…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1