Sophos
sophos
168 CVEs • 73 products
Products (73)
Click to collapseToggle
Products (73)
Click to collapse
CVEs (168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA. |
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA. |
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA. |
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA. |
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA. |
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4. |
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older. |
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1. |
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA. |
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA. |
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobi...Show more |
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older. |
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older. |
1Sophos 1Unified Threat Management Jun 17, 2026 Mar 22, 2022 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in...Show more |
1Sophos 1Unified Threat Management Jun 17, 2026 Mar 22, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710. |
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client. |
1Sophos 1Unified Threat Management Up2date Jun 17, 2026 Nov 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8. |
1Sophos 3Exploit Prevention Intercept X EndpointIntercept X For ServerJun 17, 2026 Nov 26, 2021 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanc...Show more |
1Sophos 1Sophos Secure Workspace Jun 17, 2026 Oct 30, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115. |
A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318. |