KLA10336
Multiple vulnerabilities in Sophos Web Appliance
Updated: 06/01/2019
Detect date
?
04/11/2014
Severity
?
Critical
Description

Multiple critical vulnerabilities have been found in Sophos Web Appliance. Malicious users can exploit these vulnerabilities to execute arbitrary commands or change admin password. Below is a complete list of vulnerabilities

  1. Vectors related to the netinterface configuration page can be exploited remotely via a specially designed address parameter;
  2. Vectors related to the change password dialog can be exploited remotely via a specially designed request.
Affected products

Sophos Web Appliance versions 3.8.1.1 and earlier

Solution

Update to latest version

Impacts
?
ACE 
[?]

PE 
[?]
CVE-IDS
?
CVE-2014-28498.5Critical
CVE-2014-28508.5Critical