Sophos ES1000 Email Security Appliance delivers "protection against spam, viruses, Trojans, spyware and other malware. Sophos's award-winning anti-virus engine detects all types of malware in a single, high-speed scan. Every Sophos appliance is updated with new protection intelligence every 5 minutes". During an audit of Sophos ES1000 Email Security Appliance, a Cross Site Scripting vulnerability was discovered in its web administration interface. Administration web interface is available on the public network interface, over HTTPS on port 18080.
http://www.securiteam.com/securitynews/5AP0C20NFM.html