Back

CRITICAL KEV

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code

Published Apr 4, 2023 ·Due Dec 7, 2023

Description

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Sophos
Published Apr 4, 2023
Updated Oct 21, 2025
Reserved Mar 28, 2023
CISA Vulnrichment
Updated Jan 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Sophos
Published Apr 4, 2023
Updated Oct 21, 2025
Exploited since Nov 16, 2023
EUVD-2023-23899