Sophos
Sophos Sfos: vulnerabilidades y CVE
Sophos Sfos tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas3
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1040 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 mar 2022 | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. |
| CVE-2020-12271 | Crítica (9.8) | 42% | ⚠ Explotación activa | 27 abr 2020 | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0331 | Media (5.3) | 1.5% | — | 29 mar 2022 | An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older. |
| CVE-2022-1040 | Crítica (9.8) | 100% | ⚠ Explotación activa | 25 mar 2022 | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. |
| CVE-2020-11503 | Crítica (9.8) | 1.4% | — | 18 jun 2020 | A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely. |
| CVE-2020-12271 | Crítica (9.8) | 42% | ⚠ Explotación activa | 27 abr 2020 | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration… |
| CVE-2018-16118 | Alta (8.1) | 3.7% | — | 20 jun 2019 | A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the… |
| CVE-2018-16117 | Alta (8.8) | 44% | — | 20 jun 2019 | A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName"… |
| CVE-2018-16116 | Alta (8.8) | 1.9% | — | 20 jun 2019 | SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parameter. |
| CVE-2017-18014 | Media (6.1) | 2.3% | — | 12 ene 2018 | An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Sophos
Sophos Anti-virus · 36WEB Appliance · 18Anti-virus · 12Firewall Firmware · 10Unified Threat Management Software · 9Sophos Puremessage Anti-virus · 9XG Firewall Firmware · 9Safeguard Easy Device Encryption Client · 8Sophos Small Business Suite · 8Safeguard LAN Crypt Client · 7Safeguard Enterprise Client · 7Unified Threat Management · 6