Junglewise Threat Intelligence

CVE-2016-9553: Sophos Web Appliance command injection in MgrReport.php

CVE-2016-9553 · Severity: high · CVSS 7.2 · Published 2017-01-28

Technologies: Sophos Web Appliance. Vendors: Sophos.

Executive brief

The Sophos Web Appliance, a security tool used to manage and filter web traffic, contains a vulnerability in its administrative interface. An attacker with administrative access can execute unauthorized system commands by exploiting the IP address blocking feature. This could lead to a complete takeover of the appliance, potentially allowing the attacker to intercept network traffic or disrupt security operations.

Technical details

The Sophos Web Appliance (version 4.2.1.3) contains two remote command injection vulnerabilities within the web administrative interface. The flaws exist in the 'MgrReport.php' controller, specifically within the logic responsible for blocking and unblocking IP addresses. The application fails to properly sanitize or escape input passed to the 'blockip' and 'unblockip' variables before passing them to the PHP shell_exec() function. Although the code uses a variable named 'escapedips', it does not actually perform the necessary neutralization of shell metacharacters. An authenticated attacker with administrative privileges can exploit this to execute arbitrary system commands with the privileges of the web server. The issue is addressed in version 4.3.1.

Affected products

  • Sophos Web Appliance 4.2.1.3

Timeline

  • 2016-12-12: other: Vulnerability identified by researcher
  • 2017-01-28: advisory: NVD publication date
  • 2017-02-22: other: Metasploit module published publicly

References

Related threats