CVE-2016-9553 EXPLOIT
Patch early
A public exploit exists.
Description
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device. The device doesn't properly escape the information passed in the variables 'unblockip' and 'blockip' before calling the shell_exec() function which allows for system commands to be injected into the device. The code erroneously suggests that the information handled is protected by utilizing the variable name 'escapedips' - however this was not the case. The Sophos ID is NSWA-1258.
Scoring
| CVSS | 7.2 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 19.46% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-01-28 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sophos | web appliance |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Sophos Web Appliance 4.2.1.3 - block/unblock Remote Command Injection (Metasploit) | 2016-12-12 |
References
- http://pastebin.com/DUYuN0U5
- http://swa.sophos.com/rn/swa/concepts/ReleaseNotes_4.3.1.html
- http://www.securityfocus.com/bid/95853
- https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-version-4-3-1
- http://pastebin.com/DUYuN0U5
- http://swa.sophos.com/rn/swa/concepts/ReleaseNotes_4.3.1.html
- http://www.securityfocus.com/bid/95853
- https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-version-4-3-1
→ the Explorer · watch your stack · NVD