An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSophos Cyberoamos
OSSophos≤ 2020-12-04
CISA KEV — detailsi
- Vendori
- Sophos
- Producti
- CyberoamOS
- Added to KEVi
- February 6, 2025
- Remediation deadline (US Federal)i
- February 27, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
Related vulnerabilities
Sophos Cyberoam – command injection w panelu Web Admin i SSL VPN
Pre-auth command injection w Sophos Web Appliance (RCE)
Code injection w Sophos Firewall — RCE przez User Portal i Webadmin
Authentication Bypass z możliwością RCE w Sophos Firewall
RCE w Sophos SG UTM WebAdmin — command injection bez uwierzytelnienia