APP: Sophos Web Appliance change_password Admin Password Privilege Escalation

This signature detects attempts to exploit a known flaw in Sophos Web Appliance. A successful attack may allow attackers to change admin's password allowing them to gain unauthorized access in the context of the affected user.

Extended Description

The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.

Short Name
APP:SOPHOS-WA-PWD-CHG-SSL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Admin Appliance CVE-2014-2849 Escalation Password Privilege Sophos Web change_password
Release Date
05/12/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

8.5

Found a potential security threat?