Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vf9g-3qff-2rx6

Опубликовано: 19 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.

EPSS

Процентиль: 84%
0.02324
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.

CVSS3: 9.8
fstec
около 1 года назад

Уязвимость функции email protection межсетевых экранов Sophos Firewall (ранее Sophos XG Firewall), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 84%
0.02324
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89