Web appliance firmware
This hub aggregates every CVE we track for Web appliance firmware, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
2
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2MEDIUM2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Web appliance firmware.
- CVE-2014-2849The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.8.5
- CVE-2014-2850The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address param...8.5
- CVE-2013-2642Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation ...9.3
- CVE-2013-2643Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action...4.3
- CVE-2013-2641Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.5.0
- CVE-2013-4983The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t...10.0
Product normalization is registry-driven with AI assist and human review. How it works