Sophos Firewall
cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*, +2 more
- <= 21.0.0
A business logic vulnerability has been identified in the Up2Date component of Sophos Firewall versions prior to 21.0 MR1 (20.0.1). This vulnerability allows attackers to manipulate the firewall's DNS settings, potentially leading to remote code execution.
Exploitation of this vulnerability allows for remote code execution on the affected Sophos Firewall device.
Users of Sophos Firewall versions prior to 21.0 MR1 should upgrade to version 21.0 MR1 or later. For those on version 19.0 MR2, a hotfix is available. Instructions for applying the hotfix can be found on the Sophos support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.