← Vulnerability feed

Vulnerability record · CVE-2014-2850 · published 11 April 2014

CVE-2014-2850: Sophos Web Appliance netinterface page OS command injection

Sophos · Web Appliance Firmware

The netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be passed into an OS command. An attacker with administrator access to the appliance can therefore run arbitrary commands on the underlying system. This matters because it turns a management interface into a remote code execution path on a security appliance.

8.5 CVSS 2.0 High EPSS 58% · top 0.9% CWE-78 · OS command injection
8.5CVSS 2.0 base score
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.

AV:N/AC:M/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote command execution on a security appliance with public exploit code and very high EPSS, though it requires an authenticated administrator account.

What it is

The netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be passed into an OS command. An attacker with administrator access to the appliance can therefore run arbitrary commands on the underlying system. This matters because it turns a management interface into a remote code execution path on a security appliance.

Impact

An attacker gains arbitrary command execution with the privileges of the web interface process, which on an appliance typically means full control of the host. That enables data theft, configuration tampering, or use of the appliance as a pivot into the network.

Attack surface

Reached over the network through the netinterface configuration page of the web management interface. The CVSS vector (AV:N/AC:M/Au:S) and description both indicate that a valid administrator session is required, and no user interaction beyond submitting the crafted address value is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.57697 (99th percentile) and public references include an Exploit-DB entry, indicating exploit code is publicly available. No ransomware association is documented.

What to do

  • Upgrade Sophos Web Appliance to version 3.8.2 or later, which is the fixed release named in the advisory.
  • If immediate upgrade is not possible, restrict access to the management interface to a dedicated trusted network or management VLAN.
  • Enforce strong unique credentials and multi-factor authentication for appliance administrators to reduce the value of the required admin session.
  • Audit administrator accounts and remove or disable unused ones to limit who can reach the netinterface page.

Detection

  • Review web server and appliance logs for requests to the netinterface page containing shell metacharacters such as ;, |, &, $(), or backticks in the address parameter.
  • Monitor for unexpected child processes or outbound connections originating from the appliance host.
  • Alert on configuration changes to network interface settings made outside approved change windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2850 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-1671Sophos Web Appliance pre-auth command injection in warn-proceed handlerSophos Web Appliance versions older than 4.3.10.4 contain a command injection flaw in the warn-proceed handler. Because it is reachable without authe…KEVEPSS 100%analysed10.0CVE-2013-4983Sophos Web Appliance command injection in sblistpack get_referersThe get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from en…EPSS 90%analysed9.8CVE-2017-6182Sophos web appliance os command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…EPSS 17%9.3CVE-2013-2642Sophos web appliance firmware os command injection vulnerabilitySophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …EPSS 6.9%8.5CVE-2014-2849Sophos Web Appliance change_password access control flawSophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user ch…EPSS 60%analysed8.1CVE-2017-6412Sophos web appliance vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.EPSS 7.5%7.2CVE-2022-4934Sophos web appliance command injection vulnerabilityA post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec…EPSS 1.8%7.2CVE-2017-6183Sophos web appliance command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2014-2850), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.