Lucene search

K
cveMitreCVE-2014-2850
HistoryApr 11, 2014 - 3:55 p.m.

CVE-2014-2850

2014-04-1115:55:27
CWE-78
mitre
web.nvd.nist.gov
34
sophos
web appliance
cve-2014-2850
network security
remote code execution
vulnerability

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.696

Percentile

98.1%

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.

Affected configurations

Nvd
Node
sophosweb_appliance_firmwareMatch3.7.8
OR
sophosweb_appliance_firmwareRange3.8.1.1
OR
sophosweb_appliance_firmwareMatch3.0.0
OR
sophosweb_appliance_firmwareMatch3.0.1
OR
sophosweb_appliance_firmwareMatch3.0.1.1
OR
sophosweb_appliance_firmwareMatch3.0.2
OR
sophosweb_appliance_firmwareMatch3.0.3
OR
sophosweb_appliance_firmwareMatch3.0.4
OR
sophosweb_appliance_firmwareMatch3.0.5
OR
sophosweb_appliance_firmwareMatch3.0.5.1
OR
sophosweb_appliance_firmwareMatch3.1.0
OR
sophosweb_appliance_firmwareMatch3.1.0.1
OR
sophosweb_appliance_firmwareMatch3.1.1
OR
sophosweb_appliance_firmwareMatch3.1.2
OR
sophosweb_appliance_firmwareMatch3.1.3
OR
sophosweb_appliance_firmwareMatch3.1.4
OR
sophosweb_appliance_firmwareMatch3.2.1
OR
sophosweb_appliance_firmwareMatch3.2.2
OR
sophosweb_appliance_firmwareMatch3.2.2.1
OR
sophosweb_appliance_firmwareMatch3.2.3
OR
sophosweb_appliance_firmwareMatch3.2.4
OR
sophosweb_appliance_firmwareMatch3.2.5
OR
sophosweb_appliance_firmwareMatch3.2.6
OR
sophosweb_appliance_firmwareMatch3.2.7
OR
sophosweb_appliance_firmwareMatch3.3.0
OR
sophosweb_appliance_firmwareMatch3.3.1
OR
sophosweb_appliance_firmwareMatch3.3.2
OR
sophosweb_appliance_firmwareMatch3.3.3
OR
sophosweb_appliance_firmwareMatch3.3.3.1
OR
sophosweb_appliance_firmwareMatch3.3.4
OR
sophosweb_appliance_firmwareMatch3.3.5
OR
sophosweb_appliance_firmwareMatch3.3.5.1
OR
sophosweb_appliance_firmwareMatch3.3.6
OR
sophosweb_appliance_firmwareMatch3.3.6.1
OR
sophosweb_appliance_firmwareMatch3.4.0
OR
sophosweb_appliance_firmwareMatch3.4.1
OR
sophosweb_appliance_firmwareMatch3.4.2
OR
sophosweb_appliance_firmwareMatch3.4.3
OR
sophosweb_appliance_firmwareMatch3.4.3.1
OR
sophosweb_appliance_firmwareMatch3.4.4
OR
sophosweb_appliance_firmwareMatch3.4.5
OR
sophosweb_appliance_firmwareMatch3.4.6
OR
sophosweb_appliance_firmwareMatch3.4.7
OR
sophosweb_appliance_firmwareMatch3.4.8
OR
sophosweb_appliance_firmwareMatch3.5.0
OR
sophosweb_appliance_firmwareMatch3.5.1
OR
sophosweb_appliance_firmwareMatch3.5.1.1
OR
sophosweb_appliance_firmwareMatch3.5.1.2
OR
sophosweb_appliance_firmwareMatch3.5.2
OR
sophosweb_appliance_firmwareMatch3.5.3
OR
sophosweb_appliance_firmwareMatch3.5.4
OR
sophosweb_appliance_firmwareMatch3.5.5
OR
sophosweb_appliance_firmwareMatch3.5.6
OR
sophosweb_appliance_firmwareMatch3.6.1
OR
sophosweb_appliance_firmwareMatch3.6.1.1
OR
sophosweb_appliance_firmwareMatch3.6.2
OR
sophosweb_appliance_firmwareMatch3.6.2.1
OR
sophosweb_appliance_firmwareMatch3.6.2.3
OR
sophosweb_appliance_firmwareMatch3.6.2.4.0
OR
sophosweb_appliance_firmwareMatch3.6.2.4.1
OR
sophosweb_appliance_firmwareMatch3.6.3
OR
sophosweb_appliance_firmwareMatch3.6.4
OR
sophosweb_appliance_firmwareMatch3.6.4.1
OR
sophosweb_appliance_firmwareMatch3.6.4.2
OR
sophosweb_appliance_firmwareMatch3.7.0
OR
sophosweb_appliance_firmwareMatch3.7.1
OR
sophosweb_appliance_firmwareMatch3.7.2
OR
sophosweb_appliance_firmwareMatch3.7.3
OR
sophosweb_appliance_firmwareMatch3.7.4
OR
sophosweb_appliance_firmwareMatch3.7.5
OR
sophosweb_appliance_firmwareMatch3.7.6
OR
sophosweb_appliance_firmwareMatch3.7.7
OR
sophosweb_appliance_firmwareMatch3.7.8.1
OR
sophosweb_appliance_firmwareMatch3.7.8.2
OR
sophosweb_appliance_firmwareMatch3.7.9
OR
sophosweb_appliance_firmwareMatch3.7.9.1
OR
sophosweb_appliance_firmwareMatch3.8.0
OR
sophosweb_appliance_firmwareMatch3.8.1
AND
sophosweb_applianceMatch-
VendorProductVersionCPE
sophosweb_appliance_firmware3.7.8cpe:2.3:a:sophos:web_appliance_firmware:3.7.8:*:*:*:*:*:*:*
sophosweb_appliance_firmware*cpe:2.3:o:sophos:web_appliance_firmware:*:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.0cpe:2.3:o:sophos:web_appliance_firmware:3.0.0:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.1cpe:2.3:o:sophos:web_appliance_firmware:3.0.1:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.1.1cpe:2.3:o:sophos:web_appliance_firmware:3.0.1.1:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.2cpe:2.3:o:sophos:web_appliance_firmware:3.0.2:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.3cpe:2.3:o:sophos:web_appliance_firmware:3.0.3:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.4cpe:2.3:o:sophos:web_appliance_firmware:3.0.4:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.5cpe:2.3:o:sophos:web_appliance_firmware:3.0.5:*:*:*:*:*:*:*
sophosweb_appliance_firmware3.0.5.1cpe:2.3:o:sophos:web_appliance_firmware:3.0.5.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 791

CVSS2

8.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.696

Percentile

98.1%