← Vulnerability feed

Vulnerability record · CVE-2014-2849 · published 11 April 2014

CVE-2014-2849: Sophos Web Appliance change_password access control flaw

Sophos · Web Appliance Firmware

Sophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user change the admin password with a crafted request. Because the admin account controls the appliance, this is a full compromise of the device's management plane.

8.5 CVSS 2.0 High EPSS 60% · top 0.9% CWE-264 · Permissions and access controls
8.5CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.

AV:N/AC:L/Au:S/C:N/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityA remotely reachable, publicly exploited flaw that yields full administrative takeover of the appliance, though it requires an authenticated account.

What it is

Sophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user change the admin password with a crafted request. Because the admin account controls the appliance, this is a full compromise of the device's management plane.

Impact

An attacker with any authenticated account can reset the administrator password and take over the appliance, gaining full administrative control. Integrity and availability are fully impacted; confidentiality is not per the CVSS vector.

Attack surface

Reached over the network through the web management interface's change_password function. It requires a valid authenticated session but no user interaction beyond sending the crafted request.

Exploitation

Public exploit code exists (Exploit-DB and SecurityFocus references tagged Exploit), and EPSS is 0.6032 (99th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade Sophos Web Appliance to 3.8.2 or later, per the vendor knowledge base advisory.
  • If immediate patching is not possible, restrict management interface access to trusted administrative networks.
  • Audit and remove unnecessary authenticated accounts that could reach the change_password function.
  • Monitor and rotate administrator credentials on any appliance that ran a vulnerable version.

Detection

  • Alert on change_password requests originating from non-administrative accounts or unexpected source IPs.
  • Review appliance audit logs for administrator password changes outside approved change windows.
  • Hunt for use of the public Exploit-DB proof-of-concept against the management interface.
  • Correlate unexpected admin logins or configuration changes following a password reset event.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2849 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1671Sophos Web Appliance pre-auth command injection in warn-proceed handlerSophos Web Appliance versions older than 4.3.10.4 contain a command injection flaw in the warn-proceed handler. Because it is reachable without authe…KEVEPSS 100%analysed10.0CVE-2013-4983Sophos Web Appliance command injection in sblistpack get_referersThe get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from en…EPSS 90%analysed9.8CVE-2017-6182Sophos web appliance os command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…EPSS 17%9.3CVE-2013-2642Sophos web appliance firmware os command injection vulnerabilitySophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …EPSS 6.9%8.5CVE-2014-2850Sophos Web Appliance netinterface page OS command injectionThe netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be…EPSS 58%analysed8.1CVE-2017-6412Sophos web appliance vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.EPSS 7.5%7.2CVE-2022-4934Sophos web appliance command injection vulnerabilityA post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec…EPSS 1.8%7.2CVE-2017-6183Sophos web appliance command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2014-2849), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.