CVE-2016-6597
Severity CVSS v4.0:
Pending analysis
Type:
CWE-254
Security Features
Publication date:
10/08/2016
Last modified:
12/04/2025
Description
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulnerability.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sophos:mobile_control_eas_proxy:*:*:*:*:*:*:*:* | 3.5.0.3 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/138210/Sophos-Mobile-Control-3.5.0.3-Open-Reverse-Proxy.html
- http://www.securityfocus.com/archive/1/539126/100/0/threaded
- http://www.securityfocus.com/bid/92351
- https://www.pallas.com/advisories/sophos_eas_open_reverse_proxy_vulnerability
- http://packetstormsecurity.com/files/138210/Sophos-Mobile-Control-3.5.0.3-Open-Reverse-Proxy.html
- http://www.securityfocus.com/archive/1/539126/100/0/threaded
- http://www.securityfocus.com/bid/92351
- https://www.pallas.com/advisories/sophos_eas_open_reverse_proxy_vulnerability



