Vulnerabilities
Vulnerable Software
Sophos:  Security Vulnerabilities
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
CVSS Score
7.2
EPSS Score
0.003
Published
2022-09-07
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
CVSS Score
6.8
EPSS Score
0.002
Published
2022-05-05
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
CVSS Score
8.4
EPSS Score
0.002
Published
2022-05-05
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
CVSS Score
3.9
EPSS Score
0.001
Published
2022-04-27
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
CVSS Score
5.3
EPSS Score
0.003
Published
2022-03-29
CVE-2022-1040
Known exploited
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
CVSS Score
9.8
EPSS Score
0.944
Published
2022-03-25
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
CVSS Score
8.8
EPSS Score
0.003
Published
2022-03-22
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
CVSS Score
3.3
EPSS Score
0.0
Published
2022-03-22
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.
CVSS Score
6.1
EPSS Score
0.0
Published
2022-03-08
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
CVSS Score
4.4
EPSS Score
0.001
Published
2021-11-26


Contact Us

Shodan ® - All rights reserved