Vulnerabilities > Sophos

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2021-36806 Cross-site Scripting vulnerability in Sophos Email Appliance 4.5.3.3
A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older than version 4.5.3.4.
network
low complexity
sophos CWE-79
6.1
2023-10-18 CVE-2023-5552 Insufficiently Protected Credentials vulnerability in Sophos Firewall 19.0.1/19.5.3
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
network
low complexity
sophos CWE-522
7.5
2023-07-05 CVE-2023-33335 Cross-site Scripting vulnerability in Sophos Iview
Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed.
network
low complexity
sophos CWE-79
6.1
2023-06-30 CVE-2023-33336 Cross-site Scripting vulnerability in Sophos web Appliance 4.3.9.1
Reflected cross site scripting (XSS) vulnerability was discovered in Sophos Web Appliance v4.3.9.1 that allows for arbitrary code to be inputted via the double quotes.
network
low complexity
sophos CWE-79
4.8
2023-04-04 CVE-2020-36692 Cross-site Scripting vulnerability in Sophos web Appliance
A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code in the victim browser via a malicious form that must be manually submitted by the victim while logged in to SWA.
network
low complexity
sophos CWE-79
5.4
2023-04-04 CVE-2022-4934 Command Injection vulnerability in Sophos web Appliance
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
network
low complexity
sophos CWE-77
7.2
2023-04-04 CVE-2023-1671 Command Injection vulnerability in Sophos web Appliance
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
network
low complexity
sophos CWE-77
critical
9.8
2023-03-01 CVE-2022-48309 Cross-Site Request Forgery (CSRF) vulnerability in Sophos Connect
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
network
low complexity
sophos CWE-352
4.3
2023-03-01 CVE-2022-48310 Cleartext Storage of Sensitive Information vulnerability in Sophos Connect
An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older than 2.2.90.
local
low complexity
sophos CWE-312
5.5
2023-03-01 CVE-2022-4901 Cross-site Scripting vulnerability in Sophos Connect
Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN configuration that must be manually loaded by the victim.
network
low complexity
sophos CWE-79
6.1