CVE-2023-1671: Sophos Web Appliance Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-11-16. EPSS: 100% chance of exploitation in the next 30 days.
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
Affected products
- Sophos Web Appliance: before 4.3.10.4 (fixed in 4.3.10.4)
Published 2023-04-04. Last modified 2026-06-17.