CVE-2013-4984

EUVD-2013-4828
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
sophosweb_appliance
𝑥
≤ 3.7.9
sophosweb_appliance
3.0.0
sophosweb_appliance
3.0.1
sophosweb_appliance
3.0.1.1
sophosweb_appliance
3.0.2
sophosweb_appliance
3.0.3
sophosweb_appliance
3.0.4
sophosweb_appliance
3.0.5
sophosweb_appliance
3.0.5.1
sophosweb_appliance
3.1.0
sophosweb_appliance
3.1.0.1
sophosweb_appliance
3.1.1
sophosweb_appliance
3.1.2
sophosweb_appliance
3.1.3
sophosweb_appliance
3.1.4
sophosweb_appliance
3.2.1
sophosweb_appliance
3.2.2
sophosweb_appliance
3.2.2.1
sophosweb_appliance
3.2.3
sophosweb_appliance
3.2.4
sophosweb_appliance
3.2.5
sophosweb_appliance
3.2.6
sophosweb_appliance
3.2.7
sophosweb_appliance
3.3.0
sophosweb_appliance
3.3.1
sophosweb_appliance
3.3.2
sophosweb_appliance
3.3.3
sophosweb_appliance
3.3.3.1
sophosweb_appliance
3.3.4
sophosweb_appliance
3.3.5
sophosweb_appliance
3.3.5.1
sophosweb_appliance
3.3.6
sophosweb_appliance
3.3.6.1
sophosweb_appliance
3.4.0
sophosweb_appliance
3.4.1
sophosweb_appliance
3.4.2
sophosweb_appliance
3.4.3
sophosweb_appliance
3.4.3.1
sophosweb_appliance
3.4.4
sophosweb_appliance
3.4.5
sophosweb_appliance
3.4.6
sophosweb_appliance
3.4.7
sophosweb_appliance
3.4.8
sophosweb_appliance
3.5.0
sophosweb_appliance
3.5.1
sophosweb_appliance
3.5.1.1
sophosweb_appliance
3.5.1.2
sophosweb_appliance
3.5.2
sophosweb_appliance
3.5.3
sophosweb_appliance
3.5.4
sophosweb_appliance
3.5.5
sophosweb_appliance
3.5.6
sophosweb_appliance
3.6.1
sophosweb_appliance
3.6.1.1
sophosweb_appliance
3.6.2
sophosweb_appliance
3.6.2.1
sophosweb_appliance
3.6.2.3
sophosweb_appliance
3.6.2.4.0
sophosweb_appliance
3.6.2.4.1
sophosweb_appliance
3.6.3
sophosweb_appliance
3.6.4
sophosweb_appliance
3.6.4.1
sophosweb_appliance
3.6.4.2
sophosweb_appliance
3.7.0
sophosweb_appliance
3.7.1
sophosweb_appliance
3.7.2
sophosweb_appliance
3.7.3
sophosweb_appliance
3.7.4
sophosweb_appliance
3.7.5
sophosweb_appliance
3.7.6
sophosweb_appliance
3.7.7
sophosweb_appliance
3.7.8
sophosweb_appliance
3.7.8.1
sophosweb_appliance
3.7.8.2
sophosweb_appliance
3.8.0
sophosweb_appliance
3.8.1
𝑥
= Vulnerable software versions