target entity

Sophos

7 source-linked records in the current knowledge graph.

high

CVE-2020-15069: Sophos XG Firewall Buffer Overflow Vulnerability

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-15069EPSS 10.7%SophosXG Firewall
CISA KEV ↗ · unattributed attribution
high

CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. Required action: The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CVE-2020-29574EPSS 4.7%CyberoamOSSophos
CISA KEV ↗ · unattributed attribution
high

CVE-2023-1671: Sophos Web Appliance Command Injection Vulnerability

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-1671EPSS 100.0%SophosWeb Appliance
CISA KEV ↗ · unattributed attribution
high

CVE-2020-12271: Sophos SFOS SQL Injection Vulnerability

Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). Required action: Apply updates per vendor instructions.

CVE-2020-12271EPSS 42.2%SFOSSophos
CISA KEV ↗ · unattributed attribution