Sophos Sfos 15.01.0 Mr-1.1

CPE Details

Sophos Sfos 15.01.0 Mr-1.1
15.01.0
2019-06-25
12h48 +00:00
2021-05-27
13h04 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:sophos:sfos:15.01.0:mr-1.1:*:*:*:*:*:*

Informations

Vendor

sophos

Product

sfos

Version

15.01.0

Update

mr-1.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-0331 2022-03-28 22h30 +00:00 An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
5.3
Medium
CVE-2022-1040 2022-03-25 12h10 +00:00 An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
9.8
Critical
CVE-2020-11503 2020-06-18 13h25 +00:00 A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.
9.8
Critical
CVE-2018-16117 2019-06-20 14h06 +00:00 A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.
8.8
High
CVE-2018-16118 2019-06-20 14h02 +00:00 A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.
8.1
High
CVE-2017-18014 2018-01-12 16h00 +00:00 An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server Protection") in the webadmin interface, and execute any action available to the webadmin of the firewall (e.g., creating a new user, enabling SSH, or adding an SSH authorized key). The WAF log page will execute the "User-Agent" parameter in the HTTP POST request.
6.1
Medium