APP: Sophos Web Appliance SophosConfig Arbitrary Command Execution (HTTP)

This signature detects attempts to exploit a known vulnerability in Sophos Web Appliance. A successful attack could allow the attacker to execute arbitrary commands with elevated privileges.

Extended Description

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.

Short Name
APP:SOPHOS-WEBAPP-CMDEXEC
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
(HTTP) Appliance Arbitrary CVE-2014-2850 Command Execution Sophos SophosConfig Web bid:66734
Release Date
05/21/2014
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
CVSS Score

8.5

Found a potential security threat?