Vulnerabilities > Sophos

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2022-1040 Unspecified vulnerability in Sophos Sfos
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
network
low complexity
sophos
critical
9.8
2022-03-22 CVE-2022-0386 SQL Injection vulnerability in Sophos Unified Threat Management
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
network
low complexity
sophos CWE-89
6.5
2022-03-22 CVE-2022-0652 Incorrect Permission Assignment for Critical Resource vulnerability in Sophos Unified Threat Management
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions.
local
low complexity
sophos CWE-732
7.8
2022-03-08 CVE-2021-36809 Unspecified vulnerability in Sophos SSL VPN Client
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.
local
low complexity
sophos
3.6
2021-11-26 CVE-2021-25269 Unquoted Search Path or Element vulnerability in Sophos products
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
local
low complexity
sophos CWE-428
2.1
2021-11-26 CVE-2021-36807 SQL Injection vulnerability in Sophos Unified Threat Management Up2Date
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
network
low complexity
sophos CWE-89
6.5
2021-10-30 CVE-2021-36808 Race Condition vulnerability in Sophos Secure Workspace
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
local
sophos CWE-362
4.4
2021-10-08 CVE-2021-25270 Unspecified vulnerability in Sophos Hitmanpro.Alert 3.7.6.744/861
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
local
low complexity
sophos
7.2
2021-10-08 CVE-2021-25271 Unspecified vulnerability in Sophos Hitmanpro 3.7/3.7.20
A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.
local
low complexity
sophos
3.6
2021-07-29 CVE-2021-25273 Cross-site Scripting vulnerability in Sophos Unified Threat Management
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
network
sophos CWE-79
3.5