ZeroHour

CVE-2023-1671

KEV PoC moderate

Command Injection RCE in Sophos Web Appliance Warn-Proceed Handler

CISA: Sophos Web Appliance Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Sophos Web Appliance contains a command injection flaw (CWE-77) in the handler that processes 'warn and proceed' requests from the appliance's block page, allowing untrusted input to reach a shell command. An attacker who can reach the warn-proceed endpoint sends a crafted request whose parameters inject arbitrary operating system commands, resulting in remote code execution on the appliance. Successful exploitation gives the attacker control of the appliance host, a foothold at the network perimeter, and a platform for follow-on actions such as credential theft or lateral movement. Any organization running Sophos Web Appliance, especially where the appliance's web interface or warning pages are reachable from the internet, is affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns it a 100% probability of exploitation in the next 30 days, though no public proof-of-concept is known.

What to do: Update Sophos Web Appliance to the fixed release identified in Sophos's advisory and confirm the running build is patched; restrict access to the appliance's web interface to trusted networks and review access logs for suspicious requests to the warn-proceed endpoint. If mitigations are unavailable or the deployment is on an unsupported build, follow the CISA KEV required action and discontinue use of the product.

Affected
Sophos Web ApplianceAffected version ranges not enumerated in source data; per the vendor advisory, releases prior to the patched build are vulnerable — apply the vendor's fixed re
Estimated exposure
moderate≈ low thousands of appliances (on-prem secure web gateway; public scans show only a few thousand internet-exposed instances) — Sophos Web Appliance is an on-prem perimeter appliance deployed mainly by small and mid-market organizations, and internet-wide scans historically enumerate only a few thousand exposed instances, so the plausibly affected population is in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CISA Known Exploited Vulnerability
Affected
Sophos Web Appliance
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sophos
Products
web appliance
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news