CVE-2016-9554
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing diagnostic tests with the UNIX wget utility. The application doesn't properly escape the information passed in the 'url' variable before calling the executeCommand class function ($this->dtObj->executeCommand). This function calls exec() with unsanitized user input allowing for remote command injection. The page that contains the vulnerabilities, /controllers/MgrDiagnosticTools.php, is accessed by a built-in command answered by the administrative interface. The command that calls to that vulnerable page (passed in the 'section' parameter) is: 'configuration'. Exploitation of this vulnerability yields shell access to the remote machine under the 'spiderman' user account.
- CVSS 3.0
- 7.2 HIGHCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 24.63% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- sophos/web appliance
- Source
- cve@mitre.org
References
- http://pastebin.com/UB8Ye6ZUExploit
- http://www.securityfocus.com/bid/95858Third Party Advisory, VDB Entry
- https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-version-4-3-1Release Notes
- http://pastebin.com/UB8Ye6ZUExploit
- http://www.securityfocus.com/bid/95858Third Party Advisory, VDB Entry
- https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-version-4-3-1Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.