Vulnerability record · CVE-2014-2849 · published 11 April 2014
CVE-2014-2849: Sophos Web Appliance change_password access control flaw
Sophos · Web Appliance Firmware
Sophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user change the admin password with a crafted request. Because the admin account controls the appliance, this is a full compromise of the device's management plane.
Description
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
AV:N/AC:L/Au:S/C:N/I:C/A:C
Automated analysis
high priorityA remotely reachable, publicly exploited flaw that yields full administrative takeover of the appliance, though it requires an authenticated account.
What it is
Sophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user change the admin password with a crafted request. Because the admin account controls the appliance, this is a full compromise of the device's management plane.
Impact
An attacker with any authenticated account can reset the administrator password and take over the appliance, gaining full administrative control. Integrity and availability are fully impacted; confidentiality is not per the CVSS vector.
Attack surface
Reached over the network through the web management interface's change_password function. It requires a valid authenticated session but no user interaction beyond sending the crafted request.
Exploitation
Public exploit code exists (Exploit-DB and SecurityFocus references tagged Exploit), and EPSS is 0.6032 (99th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- Upgrade Sophos Web Appliance to 3.8.2 or later, per the vendor knowledge base advisory.
- If immediate patching is not possible, restrict management interface access to trusted administrative networks.
- Audit and remove unnecessary authenticated accounts that could reach the change_password function.
- Monitor and rotate administrator credentials on any appliance that ran a vulnerable version.
Detection
- Alert on change_password requests originating from non-administrative accounts or unexpected source IPs.
- Review appliance audit logs for administrator password changes outside approved change windows.
- Hunt for use of the public Exploit-DB proof-of-concept against the management interface.
- Correlate unexpected admin logins or configuration changes following a password reset event.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2849 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2849), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.