Vulnerability record · CVE-2016-9553 · published 28 January 2017
CVE-2016-9553: Sophos web appliance command injection vulnerability
Sophos · Web Appliance
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device. The device doesn't properly escape the information passed in the variables 'unblockip' and 'blockip' before calling the shell_exec() function which allows for system commands to be injected into the device. The code erroneously suggests that the information handled is protected by utilizing the variable name 'escapedips' - however this was not the case. The Sophos ID is NSWA-1258.
Description
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device. The device doesn't properly escape the information passed in the variables 'unblockip' and 'blockip' before calling the shell_exec() function which allows for system commands to be injected into the device. The code erroneously suggests that the information handled is protected by utilizing the variable name 'escapedips' - however this was not the case. The Sophos ID is NSWA-1258.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://pastebin.com/DUYuN0U5 | Exploit |
| http://swa.sophos.com/rn/swa/concepts/ReleaseNotes_4.3.1.html | Release Notes |
| http://www.securityfocus.com/bid/95853 | Third Party AdvisoryVDB Entry |
| https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-version-4-3-1 | Release Notes |
| http://pastebin.com/DUYuN0U5 | Exploit |
| http://swa.sophos.com/rn/swa/concepts/ReleaseNotes_4.3.1.html | Release Notes |
| http://www.securityfocus.com/bid/95853 | Third Party AdvisoryVDB Entry |
| https://community.sophos.com/products/web-appliance/b/blog/posts/release-of-swa-version-4-3-1 | Release Notes |
Track CVE-2016-9553 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-9553), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.