8.1
CVSSv3

CVE-2017-6412

Published: 30/03/2017 Updated: 15/04/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Sophos Web Appliance (SWA) prior to 4.3.1.2, Session Fixation could occur, aka NSWA-1310.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos web appliance

Exploits

# Exploit Title: [Sophos Secure Web Appliance Session Fixation Vulnerability] # Date: [28/02/2017] # Exploit Author: [SlidingWindow] , Twitter: @Kapil_Khot # Vendor Homepage: [wwwsophoscom/en-us/products/secure-web-gatewayaspx] # Version: [Tested on Sophos Web Appliance version 4311 Older versions may also be affected] # Tested on: [ ...
Sophos Web Appliance version 4311 suffers from a session fixation vulnerability ...