Sophos security briefs
2 published alerts for Sophos products and services.
CyberoamOS (CROS) SQL Injection Vulnerability
Sophos CyberoamOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-29574). CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. CISA remediation due date: 2025-02-27. If you need help checking exposure, call (864) 335-9223.
Sophos SFOS SQL Injection Vulnerability
Sophos SFOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-12271). Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords). CISA remediation due date: 2022-05-03. If you need help checking exposure, call (864) 335-9223.