Vulnerability record · CVE-2014-2850 · published 11 April 2014
CVE-2014-2850: Sophos Web Appliance netinterface page OS command injection
Sophos · Web Appliance Firmware
The netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be passed into an OS command. An attacker with administrator access to the appliance can therefore run arbitrary commands on the underlying system. This matters because it turns a management interface into a remote code execution path on a security appliance.
Description
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
AV:N/AC:M/Au:S/C:C/I:C/A:C
Automated analysis
high priorityRemote command execution on a security appliance with public exploit code and very high EPSS, though it requires an authenticated administrator account.
What it is
The netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be passed into an OS command. An attacker with administrator access to the appliance can therefore run arbitrary commands on the underlying system. This matters because it turns a management interface into a remote code execution path on a security appliance.
Impact
An attacker gains arbitrary command execution with the privileges of the web interface process, which on an appliance typically means full control of the host. That enables data theft, configuration tampering, or use of the appliance as a pivot into the network.
Attack surface
Reached over the network through the netinterface configuration page of the web management interface. The CVSS vector (AV:N/AC:M/Au:S) and description both indicate that a valid administrator session is required, and no user interaction beyond submitting the crafted address value is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.57697 (99th percentile) and public references include an Exploit-DB entry, indicating exploit code is publicly available. No ransomware association is documented.
What to do
- Upgrade Sophos Web Appliance to version 3.8.2 or later, which is the fixed release named in the advisory.
- If immediate upgrade is not possible, restrict access to the management interface to a dedicated trusted network or management VLAN.
- Enforce strong unique credentials and multi-factor authentication for appliance administrators to reduce the value of the required admin session.
- Audit administrator accounts and remove or disable unused ones to limit who can reach the netinterface page.
Detection
- Review web server and appliance logs for requests to the netinterface page containing shell metacharacters such as ;, |, &, $(), or backticks in the address parameter.
- Monitor for unexpected child processes or outbound connections originating from the appliance host.
- Alert on configuration changes to network interface settings made outside approved change windows.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2850 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2850), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.