Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m7h-7mwc-924h

Опубликовано: 21 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.

EPSS

Процентиль: 49%
0.00256
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
7 месяцев назад

An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific configuration of SPX is enabled in combination with the firewall running in High Availability (HA) mode.

CVSS3: 9.8
fstec
7 месяцев назад

Уязвимость функции Secure PDF eXchange (SPX) межсетевых экранов Sophos Firewall (ранее Sophos XG Firewall), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 49%
0.00256
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-78