← Back

Sophos

sophos

168 CVEs • 73 products

Products (73)

Click to collapse
Toggle
Web Appliance
web_appliance
Anti Virus
anti-virus
Sfos
sfos
Hitmanpro
hitmanpro
Connect
connect
Firewall
firewall
Es1000
es1000
Es4000
es4000
Sophos Tester
sophos_tester
Cyberoamos
cyberoamos
Mobile
mobile
Intercept X
intercept_x
Puremessage
puremessage
Invincea X
invincea-x
Ipsec Client
ipsec_client
Cloud Optix
cloud_optix
Home
home
Ssl Vpn Client
ssl_vpn_client
Authenticator
authenticator
Iview
iview
Cyberoam
cyberoam
Xg Firewall
xg_firewall

CVEs (168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sophos
1Hitmanpro.alert
Jun 17, 2026
Oct 8, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
1Sophos
1Unified Threat Management
Jun 17, 2026
Jul 29, 2021
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
1Sophos
2Home
Intercept X
Jun 17, 2026
May 17, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.
1Sophos
1Connect
Jun 17, 2026
Mar 22, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A malicious website could execute code remotely in Sophos Connect Client before version 2.1.
1Sophos
1Cyberoamos
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
1Sophos
1Unified Threat Management
Jun 17, 2026
Sep 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
1Sophos
1Xg Firewall Firmware
Jun 17, 2026
Aug 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
1Sophos
1Xg Firewall Firmware
Jun 17, 2026
Jul 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firew...Show more
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other versions >= 17.0 have received a hotfix.Show less
1Sophos
1Xg Firewall Firmware
Jun 17, 2026
Jun 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.
1Sophos
1Sophos Secure Email
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
1Sophos
1Sfos
Jun 17, 2026
Jun 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
1Sophos
1Sfos
Jun 17, 2026
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration...Show more
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal exposed on the WAN zone. A successful attack may have caused remote code execution that exfiltrated usernames and hashed passwords for the local device admin(s), portal admins, and user accounts used for remote access (but not external Active Directory or LDAP passwords)Show less
1Sophos
2Anti Virus For Sophos Central
Anti Virus For Sophos Home
Jun 17, 2026
Apr 17, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
1Sophos
1Hitmanpro.alert
Jun 17, 2026
Mar 2, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.
1Sophos
6Cloud Optix
Endpoint ProtectionIntercept X Endpoint+3 more
Jun 17, 2026
Feb 24, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web...Show more
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.Show less
1Sophos
1Cyberoamos
Jun 17, 2026
Oct 11, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles.
1Sophos
1Sfos
Nov 21, 2024
Jun 20, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Fo...Show more
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.Show less
1Sophos
1Sfos
Nov 21, 2024
Jun 20, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST...Show more
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.Show less
1Sophos
1Sfos
Nov 21, 2024
Jun 20, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parameter.
2Ncp E
Sophos
2Ipsec Client
Ncp Secure Entry Client
Nov 21, 2024
Apr 9, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11...Show more
The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle (MITM) or man-on-the-side (MOTS) attacker to execute arbitrary, malicious software on a target user's computer. This is related to SIC_V11.04-64.exe (Sophos), NCP_EntryCl_Windows_x86_1004_31799.exe (NCP), and ncpmon.exe (both Sophos and NCP). The vulnerability exists because: (1) the VPN client requests update metadata over an insecure HTTP connection; and (2) the client software does not check if the software update is signed before running it.Show less