Записи sophos
170 опубликованных записей вендора sophos.
Профиль для исследователя
- Попали в KEV
- 7 · 4,1 %
- С эксплойтом
- 12 · 7,1 %
- Pre-auth RCE
- 30
- С записью об исправлении
- 11,2 %
- Медиана: публикация → KEV
- 546 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-264 Permissions, Privileges, and Access Controls19
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
170 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-1671Готовый эксплойт | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Критическая9,8 | KEV | 100,0 % | 4 апр. 2023 г. |
99Срочно | CVE-2022-1040Готовый эксплойт | An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version vsophos · sfos | Критическая9,8 | KEV | 99,8 % | 25 мар. 2022 г. |
99Срочно | CVE-2022-3236Готовый эксплойт | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Критическая9,8 | KEV | 98,9 % | 23 сент. 2022 г. |
98Срочно | CVE-2020-25223Готовый эксплойт | A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11sophos · unified threat management · CWE-78 | Критическая9,8 | KEV | 96,8 % | 25 сент. 2020 г. |
82Срочно | CVE-2020-12271Готовый эксплойт | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wildsophos · sfos · CWE-89 | Критическая9,8 | KEV | 42,4 % | 27 апр. 2020 г. |
72На этой неделе | CVE-2020-15069Готовый эксплойт | Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientlessophos · xg firewall firmware · CWE-120 | Критическая9,8 | KEV | 10,7 % | 29 июн. 2020 г. |
70На этой неделе | CVE-2020-29574Готовый эксплойт | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL ssophos · cyberoamos · CWE-89 | Критическая9,8 | KEV | 4,7 % | 11 дек. 2020 г. |
67На этой неделе | CVE-2013-4983Готовый эксплойт | The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers tosophos · web appliance firmware · CWE-78 | Критическая10,0 | — | 90,1 % | 10 сент. 2013 г. |
59В плане | CVE-2015-7547Proof of concept | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | Высокая8,1 | — | 91,0 % | 18 февр. 2016 г. |
52В плане | CVE-2014-2849Готовый эксплойт | The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin sophos · web appliance firmware · CWE-264 | Высокая8,5 | — | 60,3 % | 11 апр. 2014 г. |
51В плане | CVE-2015-8605Эксплойта нет | ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crashisc · dhcp · CWE-20 | Средняя6,5 | — | 82,7 % | 14 янв. 2016 г. |
51В плане | CVE-2014-2850Готовый эксплойт | The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrasophos · web appliance firmware · CWE-78 | Высокая8,5 | — | 57,7 % | 11 апр. 2014 г. |
49В плане | CVE-2004-0932Proof of concept | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attacca · etrust antivirus | Высокая7,5 | — | 63,4 % | 27 янв. 2005 г. |
48В плане | CVE-2018-16117Эксплойта нет | A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackersophos · sfos · CWE-78 | Высокая8,8 | — | 44,3 % | 20 июн. 2019 г. |
47В плане | CVE-2012-1456Эксплойта нет | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.avg · avg anti-virus · CWE-264 | Средняя4,3 | — | 99,9 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1459Эксплойта нет | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8ahnlab · v3 internet security · CWE-264 | Средняя4,3 | — | 99,8 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1446Эксплойта нет | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symanca · etrust vet antivirus · CWE-264 | Средняя4,3 | — | 99,7 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1443Эксплойта нет | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010cat · quick heal · CWE-264 | Средняя4,3 | — | 99,6 % | 21 мар. 2012 г. |
47В плане | CVE-2012-1442Эксплойта нет | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwascat · quick heal · CWE-264 | Средняя4,3 | — | 98,9 % | 21 мар. 2012 г. |
46В плане | CVE-2012-1453Эксплойта нет | The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Treca · etrust vet antivirus · CWE-264 | Средняя4,3 | — | 97,7 % | 21 мар. 2012 г. |
46В плане | CVE-2012-1430Эксплойта нет | The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning Ebitdefender · bitdefender · CWE-264 | Средняя4,3 | — | 96,0 % | 21 мар. 2012 г. |
46В плане | CVE-2012-1431Эксплойта нет | The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Secbitdefender · bitdefender · CWE-264 | Средняя4,3 | — | 96,0 % | 21 мар. 2012 г. |
45В плане | CVE-2012-1461Эксплойта нет | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Antanti-virus · vba32 · CWE-264 | Средняя4,3 | — | 91,7 % | 21 мар. 2012 г. |
45В плане | CVE-2016-0777Proof of concept | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitsophos · unified threat management software · CWE-200 | Средняя6,5 | — | 63,5 % | 14 янв. 2016 г. |
44В плане | CVE-2017-6182Proof of concept | In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remosophos · web appliance · CWE-78 | Критическая9,8 | — | 16,7 % | 30 мар. 2017 г. |
- CVE-2023-167199Срочно
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sophos · web appliance4 апр. 2023 г.
- CVE-2022-104099Срочно
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sophos · sfos25 мар. 2022 г.
- CVE-2022-323699Срочно
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sophos · firewall23 сент. 2022 г.
- CVE-2020-2522398Срочно
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %sophos · unified threat management25 сент. 2020 г.
- CVE-2020-1227182Срочно
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 42 %sophos · sfos27 апр. 2020 г.
- CVE-2020-1506972На этой неделе
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientles
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 11 %sophos · xg firewall firmware29 июн. 2020 г.
- CVE-2020-2957470На этой неделе
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL s
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 5 %sophos · cyberoamos11 дек. 2020 г.
- CVE-2013-498367На этой неделе
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to
КритическаяCVSS 10,0Готовый эксплойтEPSS 90 %sophos · web appliance firmware10 сент. 2013 г.
- CVE-2015-754759В плане
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
ВысокаяCVSS 8,1Proof of conceptEPSS 91 %gnu · glibc18 февр. 2016 г.
- CVE-2014-284952В плане
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin
ВысокаяCVSS 8,5Готовый эксплойтEPSS 60 %sophos · web appliance firmware11 апр. 2014 г.
- CVE-2015-860551В плане
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash
СредняяCVSS 6,5Эксплойта нетEPSS 83 %isc · dhcp14 янв. 2016 г.
- CVE-2014-285051В плане
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitra
ВысокаяCVSS 8,5Готовый эксплойтEPSS 58 %sophos · web appliance firmware11 апр. 2014 г.
- CVE-2004-093249В плане
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attac
ВысокаяCVSS 7,5Proof of conceptEPSS 63 %ca · etrust antivirus27 янв. 2005 г.
- CVE-2018-1611748В плане
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attacker
ВысокаяCVSS 8,8Эксплойта нетEPSS 44 %sophos · sfos20 июн. 2019 г.
- CVE-2012-145647В плане
The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.
СредняяCVSS 4,3Эксплойта нетEPSS 100 %avg · avg anti-virus21 мар. 2012 г.
- CVE-2012-145947В плане
The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8
СредняяCVSS 4,3Эксплойта нетEPSS 100 %ahnlab · v3 internet security21 мар. 2012 г.
- CVE-2012-144647В плане
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Syman
СредняяCVSS 4,3Эксплойта нетEPSS 100 %ca · etrust vet antivirus21 мар. 2012 г.
- CVE-2012-144347В плане
The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 2010
СредняяCVSS 4,3Эксплойта нетEPSS 100 %cat · quick heal21 мар. 2012 г.
- CVE-2012-144247В плане
The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwas
СредняяCVSS 4,3Эксплойта нетEPSS 99 %cat · quick heal21 мар. 2012 г.
- CVE-2012-145346В плане
The CAB file parser in Dr.Web 5.0.2.03300, Trend Micro HouseCall 9.120.0.1004, Kaspersky Anti-Virus 7.0.0.125, Sophos Anti-Virus 4.61.0, Tre
СредняяCVSS 4,3Эксплойта нетEPSS 98 %ca · etrust vet antivirus21 мар. 2012 г.
- CVE-2012-143046В плане
The ELF file parser in Bitdefender 7.2, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Secure Anti-Virus 9.0.16160.0, McAfee Anti-Virus Scanning E
СредняяCVSS 4,3Эксплойта нетEPSS 96 %bitdefender · bitdefender21 мар. 2012 г.
- CVE-2012-143146В плане
The ELF file parser in Bitdefender 7.2, Command Antivirus 5.2.11.5, Comodo Antivirus 7424, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, F-Sec
СредняяCVSS 4,3Эксплойта нетEPSS 96 %bitdefender · bitdefender21 мар. 2012 г.
- CVE-2012-146145В плане
The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Ant
СредняяCVSS 4,3Эксплойта нетEPSS 92 %anti-virus · vba3221 мар. 2012 г.
- CVE-2016-077745В плане
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensit
СредняяCVSS 6,5Proof of conceptEPSS 63 %sophos · unified threat management software14 янв. 2016 г.
- CVE-2017-618244В плане
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remo
КритическаяCVSS 9,8Proof of conceptEPSS 17 %sophos · web appliance30 мар. 2017 г.