4.7
CVSSv3

CVE-2017-6184

Published: 30/03/2017 Updated: 04/04/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 4.7 | Impact Score: 3.4 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

In Sophos Web Appliance (SWA) prior to 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos web appliance