Vulnerabilities
Vulnerable Software
Sophos:  Security Vulnerabilities
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
CVSS Score
3.9
EPSS Score
0.002
Published
2022-04-27
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
CVSS Score
5.3
EPSS Score
0.015
Published
2022-03-29
CVE-2022-1040
Known exploited
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
CVSS Score
9.8
EPSS Score
0.998
Published
2022-03-25
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
CVSS Score
8.8
EPSS Score
0.012
Published
2022-03-22
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
CVSS Score
3.3
EPSS Score
0.002
Published
2022-03-22
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client.
CVSS Score
6.1
EPSS Score
0.002
Published
2022-03-08
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
CVSS Score
4.4
EPSS Score
0.002
Published
2021-11-26
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
CVSS Score
8.8
EPSS Score
0.015
Published
2021-11-26
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
CVSS Score
5.9
EPSS Score
0.002
Published
2021-10-30
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
CVSS Score
6.7
EPSS Score
0.003
Published
2021-10-08


Contact Us

Shodan ® - All rights reserved