Executive brief
A pre-authentication command injection vulnerability exists in the warn-proceed handler of Sophos Web Appliance. An attacker can exploit this to execute arbitrary code on the appliance without prior authentication.
Affected products
- Sophos Web Appliance < 4.3.10.4
Timeline
- 2023-04-04: disclosed: NVD Published Date and Vendor Advisory date
- 2023-04-04: advisory: Sophos security advisory SA-20230404-swa-rce published
- 2023-04-26: other: Public exploit released on Packet Storm Security
- 2023-11-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-11-16: exploited: Confirmed as exploited in the wild by CISA