Vulnerabilities > Sophos > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-18 CVE-2023-5552 Insufficiently Protected Credentials vulnerability in Sophos Firewall 19.0.1/19.5.3
A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewall version 19.5 MR3 (19.5.3) and older, if the password type is set to “Specified by sender”.
network
low complexity
sophos CWE-522
7.5
2023-04-04 CVE-2022-4934 Command Injection vulnerability in Sophos web Appliance
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
network
low complexity
sophos CWE-77
7.2
2022-12-01 CVE-2022-3226 OS Command Injection vulnerability in Sophos XG Firewall Firmware 17.0/17.5/18.0
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
network
low complexity
sophos CWE-78
7.2
2022-12-01 CVE-2022-3696 Code Injection vulnerability in Sophos XG Firewall Firmware 17.0/17.5/18.0
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
network
low complexity
sophos CWE-94
7.2
2022-12-01 CVE-2022-3709 Cross-site Scripting vulnerability in Sophos XG Firewall Firmware 17.0/17.5/18.0
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
network
low complexity
sophos CWE-79
8.4
2022-12-01 CVE-2022-3713 Code Injection vulnerability in Sophos XG Firewall Firmware 17.0/17.5/18.0
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
low complexity
sophos CWE-94
8.8
2022-09-07 CVE-2022-1807 SQL Injection vulnerability in Sophos Firewall 18.5/19.0
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
network
low complexity
sophos CWE-89
7.2
2022-05-05 CVE-2021-25267 Cross-site Scripting vulnerability in Sophos Firewall Firmware
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
network
low complexity
sophos CWE-79
8.4
2022-05-05 CVE-2021-25268 Cross-site Scripting vulnerability in Sophos Firewall Firmware
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
network
low complexity
sophos CWE-79
8.4
2022-03-22 CVE-2022-0386 SQL Injection vulnerability in Sophos Unified Threat Management
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
network
low complexity
sophos CWE-89
8.8