CVE-2017-6182: OS Command Injection
Published Mar 30, 2017
·Updated
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.
Affected Software
1 affected component
Sophos Web Appliance<=4.3.1.1
Event History
Mar 30, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6182?
CVE-2017-6182 is classified as a high severity vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2017-6182?
To mitigate CVE-2017-6182, upgrade to Sophos Web Appliance version 4.3.1.2 or later.
3
What does CVE-2017-6182 affect?
CVE-2017-6182 affects Sophos Web Appliance versions prior to 4.3.1.2.
4
How was CVE-2017-6182 discovered?
CVE-2017-6182 was discovered in the report generation interface of Sophos Web Appliance.
5
What is the impact of exploiting CVE-2017-6182?
Exploiting CVE-2017-6182 could allow remote attackers to execute arbitrary commands on the affected system.