vendor:
Secure Web Appliance
by:
SlidingWindow
8,1
CVSS
HIGH
Session Fixation Vulnerability
384
CWE
Product Name: Secure Web Appliance
Affected Version From: 4.3.1.1
Affected Version To: 4.3.1.1
Patch Exists: YES
Related CWE: CVE-2017-6412
CPE: a:sophos:secure_web_appliance
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Sophos Web Appliance version 4.3.1.1
2017
Sophos Secure Web Appliance Session Fixation Vulnerability
A remote attacker could host a malicious page on his website that makes POST request to the victim’s Sophos Web Appliance to set the Session ID using STYLE parameter. The appliance does not validate if the Session ID sent by user/browser was issued by itself or fixed by an attacker. Also, the appliance does not invalidate pre-login Session IDs it issued earlier once user logs in successfully. It continues to use the same pre-login Session ID instead of invalidating it and issuing a new one.
Mitigation:
Sophos has released a patch to address this vulnerability. Users are advised to update their Sophos Web Appliance to the latest version.