← Back

CVE-2013-4984

nvd nist
Published: Sep 10, 2013Modified: Apr 29, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.

Affected (76)

1 product
Web Appliance
Configuration A
76 vulnerable
Vulnerable SoftwareAffected Versions
Sophos
Up to 3.7.9
Version 3.0.0
Version 3.0.1.1
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5.1
Version 3.0.5
Version 3.1.0.1
Version 3.1.0
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.2.1
Version 3.2.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.3.0
Version 3.3.1
Version 3.3.2
Version 3.3.3.1
Version 3.3.3
Version 3.3.4
Version 3.3.5.1
Version 3.3.5
Version 3.3.6.1
Version 3.3.6
Version 3.4.0
Version 3.4.1
Version 3.4.2
Version 3.4.3.1
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.5.0
Version 3.5.1.1
Version 3.5.1.2
Version 3.5.1
Version 3.5.2
Version 3.5.3
Version 3.5.4
Version 3.5.5
Version 3.5.6
Version 3.6.1.1
Version 3.6.1
Version 3.6.2.1
Version 3.6.2.3
Version 3.6.2.4.0
Version 3.6.2.4.1
Version 3.6.2
Version 3.6.3
Version 3.6.4.1
Version 3.6.4.2
Version 3.6.4
Version 3.7.0
Version 3.7.1
Version 3.7.2
Version 3.7.3
Version 3.7.4
Version 3.7.5
Version 3.7.6
Version 3.7.7
Version 3.7.8.1
Version 3.7.8.2
Version 3.7.8
Version 3.8.0
Version 3.8.1

References (4)

Source: cve@mitre.org
ExploitTechnical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link

Timeline

No history available yet.