Vulnerability Details CVE-2020-29574
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.106
EPSS Ranking 92.8%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
Proposed Action
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
Ransomware Campaign
Unknown
Products affected by CVE-2020-29574
-
cpe:2.3:o:sophos:cyberoamos:10.6.1
-
cpe:2.3:o:sophos:cyberoamos:10.6.2
-
cpe:2.3:o:sophos:cyberoamos:10.6.3
-
cpe:2.3:o:sophos:cyberoamos:10.6.4
-
cpe:2.3:o:sophos:cyberoamos:10.6.5
-
cpe:2.3:o:sophos:cyberoamos:10.6.6
-
cpe:2.3:o:sophos:cyberoamos:2020-12-04