Vulnerabilities
Vulnerable Software
Sophos:  >> Unified Threat Management  Security Vulnerabilities
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
CVSS Score
8.8
EPSS Score
0.003
Published
2022-03-22
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
CVSS Score
3.3
EPSS Score
0.0
Published
2022-03-22
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
CVSS Score
4.8
EPSS Score
0.002
Published
2021-07-29
CVE-2020-25223
Known exploited
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
CVSS Score
9.8
EPSS Score
0.944
Published
2020-09-25
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
CVSS Score
6.5
EPSS Score
0.806
Published
2016-01-14
Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
CVSS Score
7.8
EPSS Score
0.013
Published
2014-03-18
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
CVSS Score
4.3
EPSS Score
0.005
Published
2012-07-09


Contact Us

Shodan ® - All rights reserved