Back to Database
Status published
High
CVE-2014-2849
The Change Password dialog box (change_password) in Sophos Web Appliance...
Vulnerability Description
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-2849
Credits & Attribution
No credits recorded in the NVD database.
References
More from sophos
View All →CVE-2020-9540
Sophos HitmanPro.Alert before build 861 allows local elevation of privilege....
High
7.8
CVE-2020-9363
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass...
High
7.8
CVE-2020-29574
An SQL injection vulnerability in the WebAdmin of Cyberoam OS...
Unknown
0
CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of...
Unknown
0
CVE-2020-17352
Two OS command injection vulnerabilities in the User Portal of...
High
8.8
Affected Vendor
sophos
View all reports →Affected Software
web appliance firmware, web appliance
Vulnerable Versions:
3.7.8, 0, 3.0.0, 3.0.1, 3.0.1.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.5.1, 3.1.0, 3.1.0.1, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.2.1, 3.2.2, 3.2.2.1, 3.2.3, 3.2.4, 3.2.5, 3.2.6, 3.2.7, 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.3.1, 3.3.4, 3.3.5, 3.3.5.1, 3.3.6, 3.3.6.1, 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.4.3.1, 3.4.4, 3.4.5, 3.4.6, 3.4.7, 3.4.8, 3.5.0, 3.5.1, 3.5.1.1, 3.5.1.2, 3.5.2, 3.5.3, 3.5.4, 3.5.5, 3.5.6, 3.6.1, 3.6.1.1, 3.6.2, 3.6.2.1, 3.6.2.3, 3.6.2.4.0, 3.6.2.4.1, 3.6.3, 3.6.4, 3.6.4.1, 3.6.4.2, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.7.4, 3.7.5, 3.7.6, 3.7.7, 3.7.8.1, 3.7.8.2, 3.7.9, 3.7.9.1, 3.8.0, 3.8.1
Timeline
Official Publish:
April 11th, 2014
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.