CVE-2014-2850

high
Published 2014-04-11 · Modified 2026-05-06
CVSS v3
CVSS v2
8.5
VIR risk
8.5

Description

The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.sophos.com/en-us/support/knowledgebase/120230.aspx

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://secunia.com/advisories/57706

Application impact

VendorProductVersionsFixed
sophosweb_appliance_firmware3.7.8

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.