Junglewise Threat Intelligence

CVE-2023-1671: Sophos Web Appliance Command Injection Vulnerability

CVE-2023-1671 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-11-16

Technologies: Sophos Web Appliance. Vendors: Sophos.

Executive brief

A pre-authentication command injection vulnerability exists in the warn-proceed handler of Sophos Web Appliance. An attacker can exploit this to execute arbitrary code on the appliance without prior authentication.

Affected products

  • Sophos Web Appliance < 4.3.10.4

Timeline

  • 2023-04-04: disclosed: NVD Published Date and Vendor Advisory date
  • 2023-04-04: advisory: Sophos security advisory SA-20230404-swa-rce published
  • 2023-04-26: other: Public exploit released on Packet Storm Security
  • 2023-11-16: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-11-16: exploited: Confirmed as exploited in the wild by CISA

Related threats