CVE-2013-4984

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
sophosweb_appliance
𝑥
≤ 3.7.9
sophosweb_appliance
3.0.0
sophosweb_appliance
3.0.1
sophosweb_appliance
3.0.1.1
sophosweb_appliance
3.0.2
sophosweb_appliance
3.0.3
sophosweb_appliance
3.0.4
sophosweb_appliance
3.0.5
sophosweb_appliance
3.0.5.1
sophosweb_appliance
3.1.0
sophosweb_appliance
3.1.0.1
sophosweb_appliance
3.1.1
sophosweb_appliance
3.1.2
sophosweb_appliance
3.1.3
sophosweb_appliance
3.1.4
sophosweb_appliance
3.2.1
sophosweb_appliance
3.2.2
sophosweb_appliance
3.2.2.1
sophosweb_appliance
3.2.3
sophosweb_appliance
3.2.4
sophosweb_appliance
3.2.5
sophosweb_appliance
3.2.6
sophosweb_appliance
3.2.7
sophosweb_appliance
3.3.0
sophosweb_appliance
3.3.1
sophosweb_appliance
3.3.2
sophosweb_appliance
3.3.3
sophosweb_appliance
3.3.3.1
sophosweb_appliance
3.3.4
sophosweb_appliance
3.3.5
sophosweb_appliance
3.3.5.1
sophosweb_appliance
3.3.6
sophosweb_appliance
3.3.6.1
sophosweb_appliance
3.4.0
sophosweb_appliance
3.4.1
sophosweb_appliance
3.4.2
sophosweb_appliance
3.4.3
sophosweb_appliance
3.4.3.1
sophosweb_appliance
3.4.4
sophosweb_appliance
3.4.5
sophosweb_appliance
3.4.6
sophosweb_appliance
3.4.7
sophosweb_appliance
3.4.8
sophosweb_appliance
3.5.0
sophosweb_appliance
3.5.1
sophosweb_appliance
3.5.1.1
sophosweb_appliance
3.5.1.2
sophosweb_appliance
3.5.2
sophosweb_appliance
3.5.3
sophosweb_appliance
3.5.4
sophosweb_appliance
3.5.5
sophosweb_appliance
3.5.6
sophosweb_appliance
3.6.1
sophosweb_appliance
3.6.1.1
sophosweb_appliance
3.6.2
sophosweb_appliance
3.6.2.1
sophosweb_appliance
3.6.2.3
sophosweb_appliance
3.6.2.4.0
sophosweb_appliance
3.6.2.4.1
sophosweb_appliance
3.6.3
sophosweb_appliance
3.6.4
sophosweb_appliance
3.6.4.1
sophosweb_appliance
3.6.4.2
sophosweb_appliance
3.7.0
sophosweb_appliance
3.7.1
sophosweb_appliance
3.7.2
sophosweb_appliance
3.7.3
sophosweb_appliance
3.7.4
sophosweb_appliance
3.7.5
sophosweb_appliance
3.7.6
sophosweb_appliance
3.7.7
sophosweb_appliance
3.7.8
sophosweb_appliance
3.7.8.1
sophosweb_appliance
3.7.8.2
sophosweb_appliance
3.8.0
sophosweb_appliance
3.8.1
𝑥
= Vulnerable software versions