CVE-2023-1671: Sophos Web Appliance Command Injection Vulnerability
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
Other sources
Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of the Sophos Web Appliance firmware if vendor mitigations are unavailable; take affected appliances out of service until a mitigation or fix is provided.
Event History
Frequently Asked Questions
What is CVE-2023-1671?
CVE-2023-1671 is a pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4, allowing execution of arbitrary code.
What is the severity of CVE-2023-1671?
The severity of CVE-2023-1671 is critical with a CVSS score of 9.8.
How does CVE-2023-1671 affect Sophos Web Appliance?
CVE-2023-1671 affects Sophos Web Appliance versions older than 4.3.10.4.
How can CVE-2023-1671 be exploited?
CVE-2023-1671 can be exploited by sending specially crafted commands to the warn-proceed handler of the vulnerable Sophos Web Appliance.
How can CVE-2023-1671 be fixed?
To fix CVE-2023-1671, users should update their Sophos Web Appliance to version 4.3.10.4 or later.