Sophos Web Appliance < 4.3.1 Multiple Remote Command Injection Vulnerabilities

high Nessus Plugin ID 100846

Synopsis

A web application running on the remote host is affected by multiple remote command injection vulnerabilities.

Description

According to its self-reported version number, the Sophos Web Appliance software running on the remote host is prior to 4.3.1. It is, therefore, affected by multiple vulnerabilities :

- A remote command injection vulnerability exists in the web administration interface in the /controllers/MgrReport.php script when blocking and unblocking IP addresses due to improper validation of user-supplied input passed to the unblockip' and 'blockip' parameters. An authenticated, remote attacker can exploit this, via a specially crafted request, to inject arbitrary shell commands. (CVE-2016-9553)

- A remote command injection vulnerability exists in the web administrative interface in the /controllers/MgrDiagnosticTools.php script when performing diagnostic tests due to improper validation of user-supplied input passed to the url' parameter. An authenticated, remote attacker can exploit this, via a specially crafted request, to execute arbitrary script code in a user's browser session. (CVE-2016-9554)

Solution

Upgrade to Sophos Web Appliance version 4.3.1 or later.

See Also

http://swa.sophos.com/rn/swa/concepts/ReleaseNotes_4.3.1.html

http://www.nessus.org/u?2fa2210a

Plugin Details

Severity: High

ID: 100846

File Name: sophos_web_appliance_wsa_build_2659463.nasl

Version: 1.4

Type: remote

Family: CGI abuses

Published: 6/16/2017

Updated: 11/13/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:sophos:web_appliance

Required KB Items: installed_sw/sophos_web_protection

Exploit Available: true

Exploit Ease: No exploit is required

Patch Publication Date: 1/20/2017

Vulnerability Publication Date: 1/20/2017

Exploitable With

Core Impact

Reference Information

CVE: CVE-2016-9553, CVE-2016-9554

BID: 95853, 95858