Summary:
Sophos released security patches that patch up multiple vulnerabilities in the Sophos Web Appliance, including a serious vulnerability that allowed for code execution. The warning page handler of the appliance contained the critical flaw, identified as CVE-2023-1671 (CVSS score of 9.8), which could be exploited without authentication. the bug as a warn-proceed handler pre-auth command injection vulnerability allowing execution of arbitrary code. The exception wizard has a high-severity code execution bug. The vulnerability, identified as CVE-2022-4934 and classified as a command injection vulnerability, needs authentication to be exploited. The second is the medium-severity cross-site scripting (XSS) vulnerability in the report scheduler, CVE-2020-36692. The flaw could be used by an attacker to run JavaScript code in the victim's browser. The attack must mislead the victim into submitting a malicious form on a website controlled by the attacker while logged into Sophos Web Appliance in order to be successful.[/subscribe_to_unlock_form]
Summary:
Sophos released security patches that patch up multiple vulnerabilities in the Sophos Web Appliance, including a serious vulnerability that allowed for code execution. The warning page handler of the appliance contained the critical flaw, identified as CVE-2023-1671 (CVSS score of 9.8), which could be exploited without authentication. the bug as a warn-proceed handler pre-auth command injection vulnerability allowing execution of arbitrary code. The exception wizard has a high-severity code execution bug. The vulnerability, identified as CVE-2022-4934 and classified as a command injection vulnerability, needs authentication to be exploited. The second is the medium-severity cross-site scripting (XSS) vulnerability in the report scheduler, CVE-2020-36692. The flaw could be used by an attacker to run JavaScript code in the victim's browser. The attack must mislead the victim into submitting a malicious form on a website controlled by the attacker while logged into Sophos Web Appliance in order to be successful.[emaillocker id="1283"]
Recommendations:
References:
The following reports contain further technical details:
[/emaillocker]