CVE-2023-1671
KEV PoC moderateCommand Injection RCE in Sophos Web Appliance Warn-Proceed Handler
CISA: Sophos Web Appliance Command Injection Vulnerability
Sophos Web Appliance contains a command injection flaw (CWE-77) in the handler that processes 'warn and proceed' requests from the appliance's block page, allowing untrusted input to reach a shell command. An attacker who can reach the warn-proceed endpoint sends a crafted request whose parameters inject arbitrary operating system commands, resulting in remote code execution on the appliance. Successful exploitation gives the attacker control of the appliance host, a foothold at the network perimeter, and a platform for follow-on actions such as credential theft or lateral movement. Any organization running Sophos Web Appliance, especially where the appliance's web interface or warning pages are reachable from the internet, is affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns it a 100% probability of exploitation in the next 30 days, though no public proof-of-concept is known.
What to do: Update Sophos Web Appliance to the fixed release identified in Sophos's advisory and confirm the running build is patched; restrict access to the appliance's web interface to trusted networks and review access logs for suspicious requests to the warn-proceed endpoint. If mitigations are unavailable or the deployment is on an unsupported build, follow the CISA KEV required action and discontinue use of the product.
| Sophos Web Appliance | Affected version ranges not enumerated in source data; per the vendor advisory, releases prior to the patched build are vulnerable — apply the vendor's fixed re |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
- Affected
- Sophos Web Appliance
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sophos
- Products
- web appliance
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H