Sophos Firewall
cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*, +2 more
- <= 21.0.0
A post-authentication SQL injection vulnerability has been identified in the WebAdmin interface of Sophos Firewall. This vulnerability affects versions prior to 21.0 MR1 (21.0.1) and could allow administrators to execute arbitrary code on the firewall.
Exploitation of this vulnerability could lead to unauthorized arbitrary code execution on the affected Sophos Firewall device.
Users of Sophos Firewall versions 21.0 GA (21.0.0) and older should upgrade to a version that includes the hotfix for this vulnerability. Instructions for verifying the hotfix application are available on the Sophos support site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.