CVE-2017-6412: High severity Sophos Web Appliance vulnerability
Published Mar 30, 2017
·Updated
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
Affected Software
1 affected component
Sophos Web Appliance<=4.3.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sophos Web Appliance (SWA)to a version that resolves this vulnerability.Fixed in 4.3.1.2Patch NSWA-1310
Event History
Mar 30, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6412?
CVE-2017-6412 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2017-6412?
To fix CVE-2017-6412, upgrade the Sophos Web Appliance to version 4.3.1.2 or later.
3
What does CVE-2017-6412 affect?
CVE-2017-6412 affects Sophos Web Appliance versions prior to 4.3.1.2.
4
What type of vulnerability is CVE-2017-6412?
CVE-2017-6412 is a Session Fixation vulnerability.
5
Is CVE-2017-6412 publicly known?
Yes, CVE-2017-6412 is publicly known and was reported in the security community.