Open Reverse Proxy Vulnerability in Sophos Mobile Control Products
CVE-2016-6597

8.6HIGH

Key Information:

Vendor
Sophos
Vendor
CVE Published:
10 August 2016

Summary

The vulnerability within Sophos EAS Proxy versions prior to 6.2.0 allows remote attackers to exploit open reverse proxy functionality when Lotus Traveler is enabled. This exploitation gives unauthorized access to arbitrary web resources from the backend mail system, potentially leading to unauthorized data exposure and significant security risks.

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.