QID 731043

Date Published: 2023-12-28

QID 731043: Sophos Secure Web Appliance Multiple Vulnerabilities (sophos-sa-20230404-swa-rce)

Sophos Secure Web Appliance (SWA) works seamlessly with Sophos Secured Windows Endpoints to provide complete web protection for offsite users. The Sophos SWA is prone to multiple Remote Command Injection vulnerabilities. Affected Versions:
Sophos Secure Web Appliance prior to version 4.3.10.4

A successful exploit may impact confidentiality,integrity and availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Release of SWA v4.3.1.2 for updates and patch information.
    Vendor References

    CVEs related to QID 731043

    Software Advisories
    Advisory ID Software Component Link
    sophos-sa-20230404-swa-rce URL Logo www.sophos.com/en-us/security-advisories/sophos-sa-20230404-swa-rce