Sophos has released security updates to fix multiple vulnerabilities in Sophos Web Appliance versions older than 4.3.10.4.
The addressed vulnerabilities could allow the remote attacker to gain access, cause a cross-site scripting attack, or execute arbitrary/JavaScript code on the affected versions.
Sample of the addressed vulnerabilities:
1. Sophos Pre-auth Command Injection Vulnerability (CVE-2023-1671):
2. Sophos Post-auth Command Injection Vulnerability (CVE-2022-4934):
It should be highlighted that Sophos noted that the End of Life date for Sophos Web Appliance is on July 20, 2023.
Sophos updates are installed automatically by default; therefore, organizations should make sure that they have the most up-to-date version “4.3.10.4” available.
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |