Home
HIGH: 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 21.0 MR1 (21.0.1)
affected
Description
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 21.0 MR1 (21.0.1)
References
www.sophos.com/...ity-advisories/sophos-sa-20241219-sfos-rce