Vulnerabilities > Sophos > Firewall > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-10-18 | CVE-2023-5552 | Insufficiently Protected Credentials vulnerability in Sophos Firewall 19.0.1/19.5.3 A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”. | 7.5 |
2022-09-07 | CVE-2022-1807 | SQL Injection vulnerability in Sophos Firewall 18.5/19.0 Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1. | 7.2 |