CVE-2013-4984

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 90%
VendorProductVersion
sophosweb_appliance
𝑥
≤ 3.7.9
sophosweb_appliance
3.0.0
sophosweb_appliance
3.0.1
sophosweb_appliance
3.0.1.1
sophosweb_appliance
3.0.2
sophosweb_appliance
3.0.3
sophosweb_appliance
3.0.4
sophosweb_appliance
3.0.5
sophosweb_appliance
3.0.5.1
sophosweb_appliance
3.1.0
sophosweb_appliance
3.1.0.1
sophosweb_appliance
3.1.1
sophosweb_appliance
3.1.2
sophosweb_appliance
3.1.3
sophosweb_appliance
3.1.4
sophosweb_appliance
3.2.1
sophosweb_appliance
3.2.2
sophosweb_appliance
3.2.2.1
sophosweb_appliance
3.2.3
sophosweb_appliance
3.2.4
sophosweb_appliance
3.2.5
sophosweb_appliance
3.2.6
sophosweb_appliance
3.2.7
sophosweb_appliance
3.3.0
sophosweb_appliance
3.3.1
sophosweb_appliance
3.3.2
sophosweb_appliance
3.3.3
sophosweb_appliance
3.3.3.1
sophosweb_appliance
3.3.4
sophosweb_appliance
3.3.5
sophosweb_appliance
3.3.5.1
sophosweb_appliance
3.3.6
sophosweb_appliance
3.3.6.1
sophosweb_appliance
3.4.0
sophosweb_appliance
3.4.1
sophosweb_appliance
3.4.2
sophosweb_appliance
3.4.3
sophosweb_appliance
3.4.3.1
sophosweb_appliance
3.4.4
sophosweb_appliance
3.4.5
sophosweb_appliance
3.4.6
sophosweb_appliance
3.4.7
sophosweb_appliance
3.4.8
sophosweb_appliance
3.5.0
sophosweb_appliance
3.5.1
sophosweb_appliance
3.5.1.1
sophosweb_appliance
3.5.1.2
sophosweb_appliance
3.5.2
sophosweb_appliance
3.5.3
sophosweb_appliance
3.5.4
sophosweb_appliance
3.5.5
sophosweb_appliance
3.5.6
sophosweb_appliance
3.6.1
sophosweb_appliance
3.6.1.1
sophosweb_appliance
3.6.2
sophosweb_appliance
3.6.2.1
sophosweb_appliance
3.6.2.3
sophosweb_appliance
3.6.2.4.0
sophosweb_appliance
3.6.2.4.1
sophosweb_appliance
3.6.3
sophosweb_appliance
3.6.4
sophosweb_appliance
3.6.4.1
sophosweb_appliance
3.6.4.2
sophosweb_appliance
3.7.0
sophosweb_appliance
3.7.1
sophosweb_appliance
3.7.2
sophosweb_appliance
3.7.3
sophosweb_appliance
3.7.4
sophosweb_appliance
3.7.5
sophosweb_appliance
3.7.6
sophosweb_appliance
3.7.7
sophosweb_appliance
3.7.8
sophosweb_appliance
3.7.8.1
sophosweb_appliance
3.7.8.2
sophosweb_appliance
3.8.0
sophosweb_appliance
3.8.1
𝑥
= Vulnerable software versions