sophos records
170 published records for vendor sophos.
Researcher profile
- Entered KEV
- 7 · 4.1%
- Weaponized
- 12 · 7.1%
- Pre-auth RCE
- 30
- With a fix record
- 11.2%
- Median publish → KEV
- 546 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-264 Permissions, Privileges, and Access Controls19
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
170 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-1671Weaponized | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Critical9.8 | KEV | 100.0% | Apr 4, 2023 |
99Now | CVE-2022-1040Weaponized | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version vsophos · sfos | Critical9.8 | KEV | 99.8% | Mar 25, 2022 |
99Now | CVE-2022-3236Weaponized | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Critical9.8 | KEV | 98.9% | Sep 23, 2022 |
98Now | CVE-2020-25223Weaponized | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11sophos · unified threat management · CWE-78 | Critical9.8 | KEV | 96.8% | Sep 25, 2020 |
82Now | CVE-2020-12271Weaponized | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wildsophos · sfos · CWE-89 | Critical9.8 | KEV | 42.4% | Apr 27, 2020 |
72This week | CVE-2020-15069Weaponized | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientlessophos · xg firewall firmware · CWE-120 | Critical9.8 | KEV | 10.7% | Jun 29, 2020 |
70This week | CVE-2020-29574Weaponized | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL ssophos · cyberoamos · CWE-89 | Critical9.8 | KEV | 4.7% | Dec 11, 2020 |
67This week | CVE-2013-4983Weaponized | The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers tosophos · web appliance firmware · CWE-78 | Critical10.0 | — | 90.1% | Sep 10, 2013 |
59Plan | CVE-2015-7547Proof of concept | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | High8.1 | — | 91.0% | Feb 18, 2016 |
52Plan | CVE-2014-2849Weaponized | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin sophos · web appliance firmware · CWE-264 | High8.5 | — | 60.3% | Apr 11, 2014 |
51Plan | CVE-2015-8605No exploit | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashisc · dhcp · CWE-20 | Medium6.5 | — | 82.7% | Jan 14, 2016 |
51Plan | CVE-2014-2850Weaponized | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrasophos · web appliance firmware · CWE-78 | High8.5 | — | 57.7% | Apr 11, 2014 |
49Plan | CVE-2004-0932Proof of concept | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attacca · etrust antivirus | High7.5 | — | 63.4% | Jan 27, 2005 |
48Plan | CVE-2018-16117No exploit | A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackersophos · sfos · CWE-78 | High8.8 | — | 44.3% | Jun 20, 2019 |
47Plan | CVE-2012-1456No exploit | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Medium4.3 | — | 99.9% | Mar 21, 2012 |
47Plan | CVE-2012-1459No exploit | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Medium4.3 | — | 99.8% | Mar 21, 2012 |
47Plan | CVE-2012-1446No exploit | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Medium4.3 | — | 99.7% | Mar 21, 2012 |
47Plan | CVE-2012-1443No exploit | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Medium4.3 | — | 99.6% | Mar 21, 2012 |
47Plan | CVE-2012-1442No exploit | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwascat · quick heal · CWE-264 | Medium4.3 | — | 98.9% | Mar 21, 2012 |
46Plan | CVE-2012-1453No exploit | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Treca · etrust vet antivirus · CWE-264 | Medium4.3 | — | 97.7% | Mar 21, 2012 |
46Plan | CVE-2012-1430No exploit | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
46Plan | CVE-2012-1431No exploit | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Medium4.3 | — | 96.0% | Mar 21, 2012 |
45Plan | CVE-2012-1461No exploit | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Antanti-virus · vba32 · CWE-264 | Medium4.3 | — | 91.7% | Mar 21, 2012 |
45Plan | CVE-2016-0777Proof of concept | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitsophos · unified threat management software · CWE-200 | Medium6.5 | — | 63.5% | Jan 14, 2016 |
44Plan | CVE-2017-6182Proof of concept | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remosophos · web appliance · CWE-78 | Critical9.8 | — | 16.7% | Mar 30, 2017 |
- CVE-2023-167199Now
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sophos · web applianceApr 4, 2023
- CVE-2022-104099Now
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sophos · sfosMar 25, 2022
- CVE-2022-323699Now
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sophos · firewallSep 23, 2022
- CVE-2020-2522398Now
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
CriticalCVSS 9.8KEVWeaponizedEPSS 97%sophos · unified threat managementSep 25, 2020
- CVE-2020-1227182Now
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild
CriticalCVSS 9.8KEVWeaponizedEPSS 42%sophos · sfosApr 27, 2020
- CVE-2020-1506972This week
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles
CriticalCVSS 9.8KEVWeaponizedEPSS 11%sophos · xg firewall firmwareJun 29, 2020
- CVE-2020-2957470This week
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL s
CriticalCVSS 9.8KEVWeaponizedEPSS 5%sophos · cyberoamosDec 11, 2020
- CVE-2013-498367This week
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to
CriticalCVSS 10.0WeaponizedEPSS 90%sophos · web appliance firmwareSep 10, 2013
- CVE-2015-754759Plan
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
HighCVSS 8.1Proof of conceptEPSS 91%gnu · glibcFeb 18, 2016
- CVE-2014-284952Plan
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin
HighCVSS 8.5WeaponizedEPSS 60%sophos · web appliance firmwareApr 11, 2014
- CVE-2015-860551Plan
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash
MediumCVSS 6.5No exploitEPSS 83%isc · dhcpJan 14, 2016
- CVE-2014-285051Plan
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitra
HighCVSS 8.5WeaponizedEPSS 58%sophos · web appliance firmwareApr 11, 2014
- CVE-2004-093249Plan
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac
HighCVSS 7.5Proof of conceptEPSS 63%ca · etrust antivirusJan 27, 2005
- CVE-2018-1611748Plan
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attacker
HighCVSS 8.8No exploitEPSS 44%sophos · sfosJun 20, 2019
- CVE-2012-145647Plan
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
MediumCVSS 4.3No exploitEPSS 100%avg · avg anti-virusMar 21, 2012
- CVE-2012-145947Plan
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
MediumCVSS 4.3No exploitEPSS 100%ahnlab · v3 internet securityMar 21, 2012
- CVE-2012-144647Plan
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
MediumCVSS 4.3No exploitEPSS 100%ca · etrust vet antivirusMar 21, 2012
- CVE-2012-144347Plan
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
MediumCVSS 4.3No exploitEPSS 100%cat · quick healMar 21, 2012
- CVE-2012-144247Plan
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwas
MediumCVSS 4.3No exploitEPSS 99%cat · quick healMar 21, 2012
- CVE-2012-145346Plan
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Tre
MediumCVSS 4.3No exploitEPSS 98%ca · etrust vet antivirusMar 21, 2012
- CVE-2012-143046Plan
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-143146Plan
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
MediumCVSS 4.3No exploitEPSS 96%bitdefender · bitdefenderMar 21, 2012
- CVE-2012-146145Plan
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant
MediumCVSS 4.3No exploitEPSS 92%anti-virus · vba32Mar 21, 2012
- CVE-2016-077745Plan
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit
MediumCVSS 6.5Proof of conceptEPSS 63%sophos · unified threat management softwareJan 14, 2016
- CVE-2017-618244Plan
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remo
CriticalCVSS 9.8Proof of conceptEPSS 17%sophos · web applianceMar 30, 2017