Vulnerability record · CVE-2013-2641 · published 18 March 2014
CVE-2013-2641: Sophos Web Appliance patience.cgi directory traversal file read
Sophos · Web Appliance Firmware
Sophos Web Appliance before 3.7.8.2 contains a directory traversal flaw in patience.cgi, reachable through the id parameter. An unauthenticated remote attacker can use it to read arbitrary files on the appliance, exposing configuration and credential material on a security gateway.
Description
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read on an internet-facing security appliance with a public exploit reference and very high EPSS, though CVSS 2.0 rates it only medium.
What it is
Sophos Web Appliance before 3.7.8.2 contains a directory traversal flaw in patience.cgi, reachable through the id parameter. An unauthenticated remote attacker can use it to read arbitrary files on the appliance, exposing configuration and credential material on a security gateway.
Impact
An attacker gains read access to arbitrary files on the appliance, which can leak configuration data, credentials or other sensitive content. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network via HTTP requests to patience.cgi with a crafted id parameter. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but a public exploit reference exists and EPSS is very high (0.7099, 99.4th percentile), indicating elevated likelihood of exploitation.
What to do
- Upgrade Sophos Web Appliance to version 3.7.8.2 or later, per the vendor advisory.
- If immediate upgrade is not possible, restrict network access to the appliance management interface to trusted hosts only.
- Review appliance logs and configuration for signs of unauthorized file reads and rotate any credentials that may have been exposed.
- Monitor vendor advisories for this product line and apply subsequent security updates promptly.
Detection
- Search web or proxy logs for requests to patience.cgi containing traversal sequences such as ../ or encoded variants in the id parameter.
- Alert on unusual or repeated access to patience.cgi from unexpected source addresses.
- Review appliance file access and system logs for reads of sensitive paths outside expected application directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2641 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2641), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.