Sophos Web Appliance Pre-Authentication Command Injection (CVE-2023-1671)

critical Nessus Plugin ID 176075

Version 1.14

Mar 19, 2024, 6:40 PM

  • Logic Changes (Improving logging to reduce disk space usage)

Plugin Feed: 202403191840

Version 1.13

Feb 22, 2024, 3:51 PM

  • Logic Changes

Plugin Feed: 202402221551

Version 1.10

Feb 9, 2024, 11:22 AM

  • New

Plugin Feed: 202402091122

Version 1.8

Nov 17, 2023, 1:46 AM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")
  • CISA reference

Plugin Feed: 202311170146

Version 1.7

Nov 16, 2023, 11:33 PM

  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:F/RL:OF/RC:C")
  • CISA reference
  • CVSS temporal metrics ("CVSSv3 temporal vector" set to "CVSS:3.0/E:F/RL:O/RC:C")

Plugin Feed: 202311162333

Version 1.6

Sep 26, 2023, 8:16 PM

  • Logic Changes

Plugin Feed: 202309262016

Version 1.5

Jul 17, 2023, 5:15 PM

  • Logic Changes (Make torture_cgi library PCP clean and consolidate utf16_to_ascii())

Plugin Feed: 202307171715

Version 1.4

Jun 20, 2023, 9:07 PM

  • Logic Changes (Temporarily limit debug logging)

Plugin Feed: 202306202107

Version 1.2

Jun 1, 2023, 5:27 AM

  • Logic Changes (Better logging)

Plugin Feed: 202306010527

Version 1.1

May 19, 2023, 2:02 PM

  • Exploit attributes ("Exploit available" set to "True". "Exploitability ease" set to "Exploits are available")
  • CVSS temporal metrics ("CVSSv2 temporal vector" set to "CVSS2#E:POC/RL:OF/RC:C". "CVSSv3 temporal vector" set to "CVSS:3.0/E:P/RL:O/RC:C")

Plugin Feed: 202305191402

Version 1.0

May 19, 2023, 2:05 AM

  • New

Plugin Feed: 202305190205

* Changelogs are generally available for changes made after Nov 1, 2022