← Vulnerability feed

Vulnerability record · CVE-2023-1671 · published 4 April 2023

CVE-2023-1671: Sophos Web Appliance pre-auth command injection in warn-proceed handler

Sophos · Web Appliance

Sophos Web Appliance versions older than 4.3.10.4 contain a command injection flaw in the warn-proceed handler. Because it is reachable without authentication and allows arbitrary code execution, it is a severe remote code execution issue for any exposed appliance.

9.8 CVSS 3.1 Critical CISA KEV since 16 Nov 2023 EPSS 100% · top 0.1% CWE-77 · Command injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 pre-auth remote code execution, KEV-listed, and EPSS near 1.0 make this an urgent, actively exploited flaw.

What it is

Sophos Web Appliance versions older than 4.3.10.4 contain a command injection flaw in the warn-proceed handler. Because it is reachable without authentication and allows arbitrary code execution, it is a severe remote code execution issue for any exposed appliance.

Impact

An unauthenticated attacker can execute arbitrary commands on the appliance, gaining full control of the device and potentially pivoting into the network it protects.

Attack surface

The flaw is network-reachable via the warn-proceed handler; the CVSS vector shows no privileges required and no user interaction, so it can be triggered directly over the network.

Exploitation

CVE-2023-1671 is listed in CISA KEV with a due date of 2023-12-07, and EPSS is near 1.0 (0.99999), indicating active exploitation and very high likelihood. Public exploit code is referenced via Packet Storm.

What to do

  • Upgrade Sophos Web Appliance to version 4.3.10.4 or later immediately.
  • If patching is not possible, follow Sophos advisory SA-20230404-SWA-RCE mitigations or discontinue use of the appliance.
  • Remove or restrict network exposure of the appliance management and web interfaces to trusted networks only.
  • Monitor for and block exploitation attempts targeting the warn-proceed handler at the perimeter.
  • Verify no unauthorized changes or persistence on the appliance after patching.

Detection

  • Inspect web/proxy logs for requests to the warn-proceed handler with suspicious or shell metacharacter payloads.
  • Monitor appliance process execution for unexpected child processes spawned by the web service.
  • Alert on outbound connections from the appliance to unknown external hosts.
  • Review appliance and system logs for command execution errors or unusual file writes around the time of suspicious requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-1671 to the Known Exploited Vulnerabilities catalog on 16 November 2023 as "Sophos Web Appliance Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 December 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-1671 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-6182Sophos web appliance os command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote comman…EPSS 17%9.3CVE-2013-2642Sophos web appliance firmware os command injection vulnerabilitySophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to …EPSS 6.9%8.5CVE-2014-2849Sophos Web Appliance change_password access control flawSophos Web Appliance before 3.8.2 fails to properly restrict the Change Password dialog box (change_password), letting a remote authenticated user ch…EPSS 60%analysed8.5CVE-2014-2850Sophos Web Appliance netinterface page OS command injectionThe netinterface configuration page in Sophos Web Appliance before 3.8.2 fails to sanitize the address parameter, allowing shell metacharacters to be…EPSS 58%analysed8.1CVE-2017-6412Sophos web appliance vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.EPSS 7.5%7.2CVE-2022-4934Sophos web appliance command injection vulnerabilityA post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec…EPSS 1.8%7.2CVE-2017-6183Sophos web appliance command injection vulnerabilityIn Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers …EPSS 3.2%7.2CVE-2016-9553Sophos web appliance command injection vulnerabilityThe Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. …EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2023-1671), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.