A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
The vulnerability results from improper input handling in the email protection function, which enables injection of malicious SQL queries without prior authentication (pre-auth SQL injection). An attacker gains access to the reporting database this way. Escalation to RCE is possible only when the Secure PDF eXchange (SPX) function is simultaneously enabled and the device operates in High Availability (HA) mode.
An attacker can gain unauthorized access to the reporting database, and in a specific configuration (SPX + HA mode) — execute arbitrary code remotely on the vulnerable device, which may result in complete takeover of the firewall.
Update Sophos Firewall to version 21.0 MR1 (21.0.1) or later. Detailed information is available in the vendor's official security bulletin: https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce
Sophos Firewall in versions older than 21.0 MR1 (21.0.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSophos Firewall
HWSophosall versionsSophos Firewall Firmware
OSSophos< 21.0.1
Related vulnerabilities
Code injection w Sophos Firewall — RCE przez User Portal i Webadmin
Sophos Firewall SPX – pre-auth RCE przez zapis dowolnych plików
SQL Injection w Sophos Firewall SMTP Proxy prowadzące do RCE
Słabe dane uwierzytelniające SSH w Sophos Firewall – nieautoryzowany dostęp uprzywilejowany
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...