← Vulnerability feed

Vulnerability record · CVE-2013-2641 · published 18 March 2014

CVE-2013-2641: Sophos Web Appliance patience.cgi directory traversal file read

Sophos · Web Appliance Firmware

Sophos Web Appliance before 3.7.8.2 contains a directory traversal flaw in patience.cgi, reachable through the id parameter. An unauthenticated remote attacker can use it to read arbitrary files on the appliance, exposing configuration and credential material on a security gateway.

5.0 CVSS 2.0 Medium EPSS 71% · top 0.6% CWE-22 · Path traversal
5.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote arbitrary file read on an internet-facing security appliance with a public exploit reference and very high EPSS, though CVSS 2.0 rates it only medium.

What it is

Sophos Web Appliance before 3.7.8.2 contains a directory traversal flaw in patience.cgi, reachable through the id parameter. An unauthenticated remote attacker can use it to read arbitrary files on the appliance, exposing configuration and credential material on a security gateway.

Impact

An attacker gains read access to arbitrary files on the appliance, which can leak configuration data, credentials or other sensitive content. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reached over the network via HTTP requests to patience.cgi with a crafted id parameter. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but a public exploit reference exists and EPSS is very high (0.7099, 99.4th percentile), indicating elevated likelihood of exploitation.

What to do

  • Upgrade Sophos Web Appliance to version 3.7.8.2 or later, per the vendor advisory.
  • If immediate upgrade is not possible, restrict network access to the appliance management interface to trusted hosts only.
  • Review appliance logs and configuration for signs of unauthorized file reads and rotate any credentials that may have been exposed.
  • Monitor vendor advisories for this product line and apply subsequent security updates promptly.

Detection

  • Search web or proxy logs for requests to patience.cgi containing traversal sequences such as ../ or encoded variants in the id parameter.
  • Alert on unusual or repeated access to patience.cgi from unexpected source addresses.
  • Review appliance file access and system logs for reads of sensitive paths outside expected application directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2641 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1671Sophos Web Appliance pre-auth command injection in warn-proceed handlerSophos Web Appliance versions older than 4.3.10.4 contain a command injection flaw in the warn-proceed handler. Because it is reachable without authe…KEVEPSS 100%analysed10.0CVE-2013-4983Sophos Web Appliance command injection in sblistpack get_referersThe get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from en…EPSS 90%analysed9.8CVE-2017-6182Sophos web appliance os command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…EPSS 17%9.3CVE-2013-2642Sophos web appliance firmware os command injection vulnerabilitySophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …EPSS 6.9%8.5CVE-2014-2849Sophos Web Appliance change_password access control flawSophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user ch…EPSS 60%analysed8.5CVE-2014-2850Sophos Web Appliance netinterface page OS command injectionThe netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be…EPSS 58%analysed8.1CVE-2017-6412Sophos web appliance vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.EPSS 7.5%7.2CVE-2022-4934Sophos web appliance command injection vulnerabilityA post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2013-2641), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.