Sophos Firewall
cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*, +2 more
- <= 21.0.0
- 21.0 MR1-2 (21.0.1.277)
- <= 21.5.0
A vulnerability allowing arbitrary file writing in the Secure PDF eXchange (SPX) feature of Sophos Firewall has been identified. This issue affects versions prior to 21.0 MR2 (21.0.2) and can lead to pre-authentication remote code execution. The vulnerability arises when a specific SPX configuration is enabled, combined with the firewall operating in High Availability (HA) mode).
Exploitation of this vulnerability allows for pre-authentication remote code execution on the affected Sophos Firewall device.
Users of Sophos Firewall versions prior to 21.0 MR2 should upgrade to version 21.0 MR2 or a later version. For those on supported versions, hotfixes have been released. Instructions for verifying the hotfix can be found on the Sophos support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.