Sophos Firewall
cpe:2.3:a:sophos:firewall:*:*:*:*:*:*:*, +2 more
- <= 21.0 GA (21.0.0)
- <= 21.5 GA (21.5.0)
A SQL injection vulnerability has been identified in the legacy (transparent) SMTP proxy of Sophos Firewall. This vulnerability affects versions prior to 21.0 MR2 (21.0.2) and can lead to remote code execution. The issue arises when an email quarantining policy is active, and the firewall has been upgraded from a version earlier than 21.0 GA.
Exploitation of this vulnerability can result in remote code execution on the affected Sophos Firewall device.
Users of Sophos Firewall versions 21.0 MR1-2 (21.0.1.277) and 21.5 GA (21.5.0.171) can apply the hotfix for this vulnerability. Instructions for verifying the hotfix can be found on the Sophos support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.