vendor:
Sophos Web Appliance
by:
Behnam Abasi Vanda
7.5
CVSS
HIGH
Pre-auth command injection
78
CWE
Product Name: Sophos Web Appliance
Affected Version From: Sophos Web Appliance older than version 4.3.10.4
Affected Version To: 4.3.10.4
Patch Exists: YES
Related CWE: CVE-2023-1671
CPE: a:sophos:sophos_web_appliance:4.3.10.4
Tags: packetstorm,cve,cve2023,rce,sophos,oast
CVSS Metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Nuclei Metadata: {'max-request': 1, 'verified': True, 'shodan-query': 'title:"Sophos Web Appliance"', 'fofa-query': 'title="Sophos Web Appliance"', 'vendor': 'sophos', 'product': 'web_appliance'}
Platforms Tested: Ubuntu
2023
Sophos Web Appliance 4.3.10.4 – Pre-auth command injection
The script is an exploit for the Sophos Web Appliance version 4.3.10.4 and older that allows for pre-auth command injection. It uses the curl command to send a request to the target URL with a payload that includes a command injection. The exploit then checks if the command injection was successful by checking for a response from a specific domain. If the response is found, the script outputs 'YES' to a file.
Mitigation:
Upgrade to version 4.3.10.4 or newer.