PT-2017-10202 · Sophos · Sophos Web Appliance
Xort
·
Published
2017-01-28
·
Updated
2017-03-08
·
CVE-2016-9553
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Sophos Web Appliance version 4.2.1.3
Description
The issue affects the web administrative interface of the Sophos Web Appliance, specifically in the MgrReport.php component, which handles blocking and unblocking IP addresses. The problem arises from the improper escaping of information passed in the
unblockip and blockip variables before they are used in the shell exec() function, allowing system commands to be injected. This occurs despite the variable name escapedips suggesting protection.Recommendations
For Sophos Web Appliance version 4.2.1.3, as a temporary workaround, consider restricting access to the MgrReport.php component, specifically the /controllers/MgrReport.php endpoint, to minimize the risk of exploitation. Avoid using the
unblockip and blockip variables in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sophos Web Appliance