Sophos
Sophos Unified Threat Management: vulnerabilidades y CVE
Sophos Unified Threat Management tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-25223 | Crítica (9.8) | 97% | ⚠ Explotación activa | 25 sept 2020 | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0652 | Alta (7.8) | 0.19% | — | 22 mar 2022 | Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in… |
| CVE-2022-0386 | Alta (8.8) | 1.2% | — | 22 mar 2022 | A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710. |
| CVE-2021-25273 | Media (4.8) | 0.83% | — | 29 jul 2021 | Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706. |
| CVE-2020-25223 | Crítica (9.8) | 97% | ⚠ Explotación activa | 25 sept 2020 | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 |
| CVE-2014-2537 | Alta (7.8) | 3.1% | — | 18 mar 2014 | Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. |
| CVE-2012-3238 | Media (4.3) | 3.5% | — | 9 jul 2012 | Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)"… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Sophos
Sophos Anti-virus · 36WEB Appliance · 18Anti-virus · 12Firewall Firmware · 10XG Firewall Firmware · 9Unified Threat Management Software · 9Sophos Puremessage Anti-virus · 9Safeguard Easy Device Encryption Client · 8Sfos · 8Sophos Small Business Suite · 8Safeguard LAN Crypt Client · 7Safeguard Enterprise Client · 7