CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2020-29574

CVSS 9.8v3.1pub. 2020-12-11upd. 2026-08-15

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sophos Cyberoamos

    OS
    Sophos
    ≤ 2020-12-04

CISA KEV — detailsi

Vendori
Sophos
Producti
CyberoamOS
Added to KEVi
February 6, 2025
Remediation deadline (US Federal)i
February 27, 2025(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CISA descriptioni

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 27 lutego 2025
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2019-17059CRITICAL9.8PL ✓same product

Sophos Cyberoam – command injection w panelu Web Admin i SSL VPN

CVE-2023-1671CRITICAL9.8⚠ KEVPL ✓same vendor

Pre-auth command injection w Sophos Web Appliance (RCE)

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓same vendor

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2022-1040CRITICAL9.8⚠ KEVPL ✓same vendor

Authentication Bypass z możliwością RCE w Sophos Firewall

CVE-2020-25223CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Sophos SG UTM WebAdmin — command injection bez uwierzytelnienia