LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-1671: Sophos Web Appliance Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 16, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 7, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-1671 to its Known Exploited Vulnerabilities catalog on Nov 16, 2023, with a federal patch deadline of Dec 7, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.

CVE-2023-1671 is a command injection vulnerability in Sophos Web Appliance that can allow an attacker to achieve remote code execution. It matters because web appliances often sit at network edges or choke points for traffic inspection and policy enforcement; successful abuse can give an attacker a foothold to run commands on the device itself, potentially leading to further compromise of connected systems or interception of traffic. Public detail is limited to the facts below; confirm exact impact, versions, and fixes against the vendor advisory.

CISA notes that the flaw resides in the warn-proceed handler and that organizations should apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command). In products of this class, user-controlled or request-controlled input reaches a shell or command interpreter without sufficient sanitization or parameterization. An attacker who can reach the vulnerable handler can supply crafted input that the application treats as part of an operating-system command rather than pure data.

According to the CISA summary, the specific entry point is the warn-proceed handler in Sophos Web Appliance. Successful injection yields remote code execution on the appliance. Exact request format, authentication requirements, and payload construction are not provided here; treat any public proof-of-concept material with caution and verify behavior only against the vendor advisory and your own controlled testing.

Am I affected? How to find it in your systems

Sophos Web Appliance is typically deployed as a dedicated appliance or virtual appliance that proxies or filters web traffic for an organization. Inventory every instance that performs URL filtering, SSL inspection, or related web-security functions. Check management consoles, asset databases, network diagrams, and configuration-management tools for hosts running the product.

If the product is end-of-life or no longer supported, treat it as high risk regardless of version.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation instructions for CVE-2023-1671 as soon as they can be validated in a test environment. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to a command-injection flaw on a network appliance.

If your data may have been exposed

Actively exploited vulnerabilities of this class frequently lead to breaches in which credentials, session data, or internal network access are obtained. If you have reason to believe the appliance was compromised, isolate it, preserve logs and memory images, and begin incident-response procedures. Review any data that transited the device for potential exposure. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related accounts appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSophos · Web Appliance
WeaknessCWE-77
Added to CISA KEVNov 16, 2023
Federal patch deadlineDec 7, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities