Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Web Appliance CRITICAL 9.8
CVE-2023-1671 KEVEPSS 100%

A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitr…

Fix: 4.3.10.4+
Fix from $2,300 2023-04-04
Firewall CRITICAL 9.8
CVE-2022-3236 KEVEPSS 99%

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and olde…

Fix: after 19.0.1
Fix from $2,300 2022-09-23
Sfos CRITICAL 9.8
CVE-2022-1040 KEVEPSS 100%

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 …

Fix: after 18.5.3
Fix from $2,300 2022-03-25
Cyberoamos CRITICAL 9.8
CVE-2020-29574 KEV

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements…

Fix: after 2020-12-04
Fix from $2,300 2020-12-11
Unified Threat Management CRITICAL 9.8
CVE-2020-25223 KEVEPSS 97%

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Fix: 9.511 / 9.607+
Fix from $2,300 2020-09-25
Xg Firewall Firmware CRITICAL 9.8
CVE-2020-15069 KEVEPSS 11%

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.…

Fix: 17.5+
Fix from $2,300 2020-06-29
Sfos CRITICAL 9.8
CVE-2020-12271 KEVEPSS 42%

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April…

Mitigation only
Fix from $2,300 2020-04-27