← Back

Unified Threat Management

unified_threat_management

Vendor: Sophos • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sophos
1Unified Threat Management
Jun 17, 2026
Mar 22, 2022
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in...Show more
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.Show less
1Sophos
1Unified Threat Management
Jun 17, 2026
Mar 22, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
1Sophos
1Unified Threat Management
Jun 17, 2026
Jul 29, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
1Sophos
1Unified Threat Management
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
1Sophos
2Unified Threat Management
Unified Threat Management Software
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
2Astaro
Sophos
4Security Gateway
Security Gateway SoftwareUnified Threat Management+1 more
Apr 29, 2026
Jul 9, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" fie...Show more
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.Show less