CVE-2022-4934: Command Injection
Published Apr 4, 2023
·Updated
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
Affected Software
1 affected component
Sophos Web Appliance<4.3.10.4
Event History
Apr 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4934?
CVE-2022-4934 is a post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4.
2
How severe is CVE-2022-4934?
CVE-2022-4934 has a severity score of 7.2, which is considered high.
3
How does CVE-2022-4934 impact Sophos Web Appliance?
CVE-2022-4934 allows administrators to execute arbitrary code on Sophos Web Appliance.
4
Which versions of Sophos Web Appliance are affected?
Sophos Web Appliance versions older than 4.3.10.4 are affected by CVE-2022-4934.
5
How can I fix CVE-2022-4934?
To fix CVE-2022-4934, update Sophos Web Appliance to version 4.3.10.4 or later.