CRITICAL🇵🇱 Wersja polska

CVE-2024-12727

CVSS 9.8v3.1pub. 2024-12-19upd. 2025-11-12

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.

🤖 AI Analysis
How it works

The vulnerability results from improper input handling in the email protection function, which enables injection of malicious SQL queries without prior authentication (pre-auth SQL injection). An attacker gains access to the reporting database this way. Escalation to RCE is possible only when the Secure PDF eXchange (SPX) function is simultaneously enabled and the device operates in High Availability (HA) mode.

Impact

An attacker can gain unauthorized access to the reporting database, and in a specific configuration (SPX + HA mode) — execute arbitrary code remotely on the vulnerable device, which may result in complete takeover of the firewall.

Mitigation & patch

Update Sophos Firewall to version 21.0 MR1 (21.0.1) or later. Detailed information is available in the vendor's official security bulletin: https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce

Who is affected

Sophos Firewall in versions older than 21.0 MR1 (21.0.1)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sophos Firewall

    HW
    Sophos
    all versions
  • Sophos Firewall Firmware

    OS
    Sophos
    < 21.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCESQLiFirewall
CWE
References

Related vulnerabilities

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓same product

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2025-6704CRITICAL9.8PL ✓same product

Sophos Firewall SPX – pre-auth RCE przez zapis dowolnych plików

CVE-2025-7624CRITICAL9.8PL ✓same product

SQL Injection w Sophos Firewall SMTP Proxy prowadzące do RCE

CVE-2024-12728CRITICAL9.8PL ✓same product

Słabe dane uwierzytelniające SSH w Sophos Firewall – nieautoryzowany dostęp uprzywilejowany

CVE-2024-13974HIGH8.1same product

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...