CVE-2014-2849: Sophos Web Appliance

High severity, CVSS 8.5. EPSS: 60.9% chance of exploitation in the next 30 days.

The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.

Affected products

  • Sophos Web Appliance
  • Sophos Web Appliance Firmware: version 3.7.8 only; up to and including 3.8.1.1; version 3.0.0 only; version 3.0.1 only; version 3.0.1.1 only; version 3.0.2 only; …

Published 2014-04-11. Last modified 2026-06-17.