Show filters
163 Total Results
Displaying 21-30 of 163
Sort by:
Attacker Value
Unknown

CVE-2022-48309

Disclosure Date: March 01, 2023 (last updated October 08, 2023)
A CSRF vulnerability allows malicious websites to retrieve logs and technical support archives in Sophos Connect versions older than 2.2.90.
Attacker Value
Unknown

CVE-2022-3713

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3711

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3710

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3709

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3696

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3226

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3980

Disclosure Date: November 16, 2022 (last updated December 22, 2024)
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
Attacker Value
Unknown

CVE-2022-1807

Disclosure Date: September 07, 2022 (last updated October 08, 2023)
Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
Attacker Value
Unknown

CVE-2021-25268

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.