CISA adds Sophos Web Appliance bug to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-1671 | Command Injection RCE in Sophos Web Appliance Warn-Proceed Handler Sophos Web Appliance contains a command injection flaw (CWE-77) in the handler that processes 'warn and proceed' requests from the appliance's block page, allowing untrusted input to reach a shell command. An attacker who can reach the warn-proceed endpoint sends a crafted request whose parameters inject arbitrary operating system commands, resulting in remote code execution on the appliance. Successful exploitation gives the attacker control of the appliance host, a foothold at the network perimeter, and a platform for follow-on actions such as credential theft or lateral movement. Any organization running Sophos Web Appliance, especially where the appliance's web interface or warning pages are reachable from the internet, is affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns it a 100% probability of exploitation in the next 30 days, though no public proof-of-concept is known. Do: Update Sophos Web Appliance to the fixed release identified in Sophos's advisory and confirm the running build is patched; restrict access to the appliance's web interface to trusted networks and review access logs for suspicious requests to the warn-proceed endpoint. If mitigations are unavailable or the deployment is on an unsupported build, follow the CISA KEV required action and discontinue use of the product. | 9.8 | 100% | KEV PoC |
| moderate≈ low thousands of appliances (on-prem secure web gateway; public scans show only a few thousand internet-exposed instances) | |
| CVE-2023-2551 | PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2023-36584 | Mark of the Web (MOTW) Security Feature Bypass in Microsoft Windows Microsoft Windows' Mark of the Web (MOTW) feature, which tags files downloaded from the internet so that security checks such as SmartScreen warnings and opening restrictions can apply, fails to correctly apply the mark in affected Windows versions. An attacker can trigger the bypass by delivering a crafted file over the network (typically downloaded or opened by a user), so Windows treats the file as originating from a trusted local source; the CVSS vector confirms network attack surface with required user interaction (AV:N/UI:R). A successful bypass lets a specially crafted application run without the security warnings and restrictions normally applied to internet-originated files, weakening endpoint defenses during malware delivery (per CVSS, integrity and availability are partially impacted with no confidentiality impact from the bypass itself). Any organization or user running Windows 10 (1507, 1809, 21H1, 22H2), Windows 11 (21H2, 22H2), or Windows Server 2008 through 2022 is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-16, confirming in-the-wild exploitation, and EPSS assigns a roughly 3.1% probability of exploitation in the next 30 days (87th percentile); no public proof-of-concept is known. Do: Apply the November 2023 Windows cumulative security updates for each affected Windows 10, Windows 11, and Windows Server version, consistent with CISA's KEV required action (apply vendor mitigations or discontinue use if updates are unavailable). Prioritize user workstations and any systems where users open downloaded files or documents, since exploitation requires user interaction with a crafted internet-delivered file. Verify patch coverage across all listed Windows branches, as exploitation is confirmed in the wild and the primary gain is defeating MOTW-based warnings to aid malware delivery. | 5.4 | 3% | KEV |
| mass≈1 billion+ installations (Windows 10/11 desktop installed base plus widely deployed Windows Server versions) |
Full article201 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 17, 2023

US CISA added three new vulnerabilities (tracked as CVE-2023-36584, CVE-2023-1671, and CVE-2023-2551) to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Below is the list of the three added vulnerabilities:
- CVE-2023-36584 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
- CVE-2023-1671 Sophos Web Appliance Command Injection Vulnerability. The CVE-2023-1671 flaw is a pre-auth command injection issue that resides in the warn-proceed handler, it affects appliances older than version 4.3.10.4.
- CVE-2023-2551 Oracle Fusion Middleware Unspecified Vulnerability. The issue is a PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix these vulnerabilities by November 17, 2023.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/154310/security/cisa-known-exploited-vulnerabilities-catalog-17-nov-23.html