Show filters
163 Total Results
Displaying 31-40 of 163
Sort by:
Attacker Value
Unknown
CVE-2021-25267
Disclosure Date: May 05, 2022 (last updated October 07, 2023)
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
0
Attacker Value
Unknown
CVE-2021-25266
Disclosure Date: April 27, 2022 (last updated October 07, 2023)
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
0
Attacker Value
Unknown
CVE-2022-0331
Disclosure Date: March 29, 2022 (last updated October 07, 2023)
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
0
Attacker Value
Unknown
CVE-2022-0652
Disclosure Date: March 22, 2022 (last updated November 08, 2023)
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
0
Attacker Value
Unknown
CVE-2022-0386
Disclosure Date: March 22, 2022 (last updated October 07, 2023)
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
0
Attacker Value
Unknown
CVE-2021-36809
Disclosure Date: March 08, 2022 (last updated October 07, 2023)
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.
0
Attacker Value
Unknown
CVE-2021-36807
Disclosure Date: November 26, 2021 (last updated October 07, 2023)
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
0
Attacker Value
Unknown
CVE-2021-25269
Disclosure Date: November 26, 2021 (last updated October 07, 2023)
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
0
Attacker Value
Unknown
CVE-2021-36808
Disclosure Date: October 30, 2021 (last updated November 28, 2024)
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
0
Attacker Value
Unknown
CVE-2021-25271
Disclosure Date: October 08, 2021 (last updated November 28, 2024)
A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.
0