Sophos Unified Threat Management vulnerabilities

6 known vulnerabilities affecting sophos/unified_threat_management.

Total CVEs
6
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-0652HIGHCVSS 7.8fixed in 9.7102022-03-22
CVE-2022-0652 [HIGH] CWE-532 CVE-2022-0652: Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure ac Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
nvd
CVE-2022-0386HIGHCVSS 8.8fixed in 9.7102022-03-22
CVE-2022-0386 [HIGH] CWE-89 CVE-2022-0386: A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated atta A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
nvd
CVE-2021-25273MEDIUMCVSS 4.8fixed in 9.7062021-07-29
CVE-2021-25273 [MEDIUM] CWE-79 CVE-2021-25273: Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before versio Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
nvd
CVE-2020-25223CRITICALCVSS 9.8KEVPoCfixed in 9.511≥ 9.600, < 9.607+4 more2020-09-25
CVE-2020-25223 [CRITICAL] CWE-78 CVE-2020-25223: A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9. A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
nvd
CVE-2014-2537HIGHCVSS 7.8v110v120+5 more2014-03-18
CVE-2014-2537 [HIGH] CWE-399 CVE-2014-2537: Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cau Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
nvd
CVE-2012-3238MEDIUMCVSS 4.3v110v120+5 more2012-07-09
CVE-2012-3238 [MEDIUM] CWE-79 CVE-2012-3238: Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Secur Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
nvd