Threat Advisory

Sophos Patches Critical Code Execution Vulnerability in Web Security Appliance

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Sophos released security patches that patch up multiple vulnerabilities in the Sophos Web Appliance, including a serious vulnerability that allowed for code execution. The warning page handler of the appliance contained the critical flaw, identified as CVE-2023-1671 (CVSS score of 9.8), which could be exploited without authentication. the bug as a warn-proceed handler pre-auth command injection vulnerability allowing execution of arbitrary code. The exception wizard has a high-severity code execution bug. The vulnerability, identified as CVE-2022-4934 and classified as a command injection vulnerability, needs authentication to be exploited. The second is the medium-severity cross-site scripting (XSS) vulnerability in the report scheduler, CVE-2020-36692. The flaw could be used by an attacker to run JavaScript code in the victim's browser. The attack must mislead the victim into submitting a malicious form on a website controlled by the attacker while logged into Sophos Web Appliance in order to be successful.[/subscribe_to_unlock_form]

Summary:

Sophos released security patches that patch up multiple vulnerabilities in the Sophos Web Appliance, including a serious vulnerability that allowed for code execution. The warning page handler of the appliance contained the critical flaw, identified as CVE-2023-1671 (CVSS score of 9.8), which could be exploited without authentication. the bug as a warn-proceed handler pre-auth command injection vulnerability allowing execution of arbitrary code. The exception wizard has a high-severity code execution bug. The vulnerability, identified as CVE-2022-4934 and classified as a command injection vulnerability, needs authentication to be exploited. The second is the medium-severity cross-site scripting (XSS) vulnerability in the report scheduler, CVE-2020-36692. The flaw could be used by an attacker to run JavaScript code in the victim's browser. The attack must mislead the victim into submitting a malicious form on a website controlled by the attacker while logged into Sophos Web Appliance in order to be successful.[emaillocker id="1283"]

Recommendations:

  • We strongly recommend you apply the fix released for Sophos Web Appliance (SWA) 4.3.10.4
  • There is no action required for Sophos Web Appliance customers, as updates are installed automatically by default.
  • Sophos recommends against accessing the Sophos Web Appliance on the open Internet or without a firewall.

References:

The following reports contain further technical details:

https://www.securityweek.com/sophos-patches-critical-code-execution-vulnerability-in-web-security-appliance/

[/emaillocker]
crossmenu