EUVD-2023-23899
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 16 Nov 2023. Evidence sources: cisa_kev.
- ENISA score
- 9.8 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
