CVE-2017-6184: Command Injection
Published Mar 30, 2017
·Updated
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.
Affected Software
1 affected component
Sophos Web Appliance<=4.3.1.1
Event History
Mar 30, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6184?
CVE-2017-6184 has been rated as a high severity vulnerability due to its potential for remote command injection.
2
How do I fix CVE-2017-6184?
To fix CVE-2017-6184, upgrade the Sophos Web Appliance to version 4.3.1.2 or later.
3
What type of vulnerability is CVE-2017-6184?
CVE-2017-6184 is a remote command injection vulnerability found in the report generation interface of Sophos Web Appliance.
4
Which versions of Sophos Web Appliance are affected by CVE-2017-6184?
CVE-2017-6184 affects Sophos Web Appliance versions prior to 4.3.1.2.
5
Can CVE-2017-6184 be exploited remotely?
Yes, CVE-2017-6184 can be exploited remotely through the token parameter in the web interface.