Sophos Firewall
cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*, +2 more
- <= 21.0.0
A command injection vulnerability has been identified in the WebAdmin interface of Sophos Firewall. This vulnerability affects versions prior to 21.0 MR2 (21.0.2) and allows adjacent attackers to execute code on High Availability (HA) auxiliary devices without authentication, provided that One-Time Password (OTP) authentication is enabled for the admin user.
Exploitation of this vulnerability could lead to unauthorized pre-authentication code execution on High Availability auxiliary devices.
Users should upgrade to Sophos Firewall version 21.0 MR2 or later. Hotfixes for this vulnerability have been released for several supported versions. Instructions for verifying the hotfix can be found in the Sophos Knowledge Base.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.