CVE-2023-1671

Sophos Web Appliance Command Injection Vulnerability

9.8
CVSS 3.1
100.0 %
EPSS (current)
2023-11-16
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Sophos / Web Appliance

Published: 2023-04-04 · Due (CISA): 2023-12-07

CWE: CWE-77 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2023/CVE-2023-1671.yamlSophos Web Appliance - Remote Code Execution–
exploitdb51396Sophos Web Appliance 4.3.10.4 - Pre-auth command injection2023-04-25

References only — no downloads or instructions.

Sources