← Vulnerability feed

Vulnerability record · CVE-2013-4983 · published 10 September 2013

CVE-2013-4983: Sophos Web Appliance command injection in sblistpack get_referers

Sophos · Web Appliance Firmware

The get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from end-user/index.php to a shell without sanitizing shell metacharacters. A remote attacker can inject commands that execute with the privileges of the appliance process. Because the appliance sits inline on web traffic, compromise can expose or disrupt all proxied user activity.

10.0 CVSS 2.0 High EPSS 90% · top 0.2% CWE-78 · OS command injection
10.0CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 10.0 with network reachability, no authentication, full command execution, public exploit references, and a very high EPSS score make this an urgent patch.

What it is

The get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from end-user/index.php to a shell without sanitizing shell metacharacters. A remote attacker can inject commands that execute with the privileges of the appliance process. Because the appliance sits inline on web traffic, compromise can expose or disrupt all proxied user activity.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the appliance, gaining full control of the device and any credentials or traffic it handles. This can lead to data theft, traffic manipulation, or use of the appliance as a pivot into the internal network.

Attack surface

Reachable over the network through end-user/index.php by supplying a crafted domain parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is 0.90133 (99.789th percentile) and the references include an Exploit-tagged Core Security advisory, indicating public exploit material exists and exploitation is likely.

What to do

  • Upgrade Sophos Web Appliance to 3.7.9.1 or 3.8.1.1 (or later) as directed in Sophos knowledge base article 119773.
  • If immediate patching is not possible, restrict network access to the end-user interface to trusted management networks only.
  • Monitor and review the appliance for signs of compromise, and rotate any credentials or certificates stored on or passing through it.
  • Apply input validation or a WAF rule blocking shell metacharacters in the domain parameter as a temporary compensating control.

Detection

  • Inspect web and proxy logs for requests to end-user/index.php with shell metacharacters (;, |, &, $, backticks) in the domain parameter.
  • Monitor appliance process execution for unexpected child processes spawned by sblistpack or the web server.
  • Alert on outbound connections from the appliance to unfamiliar hosts, which may indicate command-and-control or data exfiltration.
  • Review appliance and system logs for command execution errors or unusual activity around sblistpack.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-4983 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2013-2642Sophos web appliance firmware os command injection vulnerabilitySophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …EPSS 6.9%8.5CVE-2014-2849Sophos Web Appliance change_password access control flawSophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user ch…EPSS 60%analysed8.5CVE-2014-2850Sophos Web Appliance netinterface page OS command injectionThe netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be…EPSS 58%analysed5.0CVE-2013-2641Sophos Web Appliance patience.cgi directory traversal file readSophos Web Appliance before 3.7.8.2 contains a directory traversal flaw in patience.cgi, reachable through the id parameter. An unauthenticated remot…EPSS 71%analysed4.3CVE-2013-2643Sophos web appliance firmware cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or H…EPSS 4.5%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed

Source: NIST National Vulnerability Database (record CVE-2013-4983), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.