peter bassill · operator
$ cve CVE-2014-2850 JSON

CVE-2014-2850 EXPLOIT

8.5
HIGH · CVSS 2.0 · EPSS 57.7% (pctl 99)

Patch early

A public exploit exists.

Description

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.

Scoring

CVSS8.5 (HIGH, v2.0)
VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
EPSS57.7% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2014-04-11
Last modified2026-06-17

Affected (2)

VendorProduct
sophosweb appliance
sophosweb appliance firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD