Skip to main content

Vendor/product archive

sophos / xg_firewall CVEs

Beta · best-effort

13 CVEs tagged to sophos / xg_firewall3 Critical, 6 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2022-3711

Published Dec 1, 2022

A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than vers…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3710

Published Dec 1, 2022

A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3709

Published Dec 1, 2022

A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-15069

Published Jun 29, 2020

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was publish…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-11503

Published Jun 18, 2020

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-12271

Published Apr 27, 2020

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices c…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
57.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-16118

Published Jun 20, 2019

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS comm…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16117

Published Jun 20, 2019

A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16116

Published Jun 20, 2019

SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18014

Published Jan 12, 2018

An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability fou…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1