CRITICAL🇵🇱 Wersja polska

CVE-2024-12728

CVSS 9.8v3.1pub. 2024-12-19upd. 2025-11-12

A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).

🤖 AI Analysis
How it works

The vulnerability classified as CWE-1391 (use of weak credentials) means that Sophos Firewall in versions earlier than 20.0 MR3 possesses predictable or default login credentials for the SSH service. A remote attacker, without any prior authentication, can exploit these weak credentials to log in via SSH. Upon successful authentication, they gain privileged access to the operating system of the device.

Impact

An attacker can gain full, privileged access to the Sophos Firewall system, enabling them to read sensitive configuration, modify firewall rules, take control of the network device, and potentially perform further lateral movement within the infrastructure protected by the device.

Mitigation & patch

Update Sophos Firewall to version 20.0 MR3 (20.0.3) or newer. As a temporary workaround, it is recommended to restrict SSH access to the device exclusively to trusted IP addresses and change default credentials. Details are available in the vendor advisories: https://www.sophos.com/en-us/security-advisories/sophos-sa-20241219-sfos-rce

Who is affected

Sophos Firewall Firmware and Sophos Firewall in versions earlier than 20.0 MR3 (20.0.3)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Sophos Firewall

    HW
    Sophos
    all versions
  • Sophos Firewall Firmware

    OS
    Sophos
    < 20.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Firewall
CWE
References

Related vulnerabilities

CVE-2022-3236CRITICAL9.8⚠ KEVPL ✓same product

Code injection w Sophos Firewall — RCE przez User Portal i Webadmin

CVE-2025-6704CRITICAL9.8PL ✓same product

Sophos Firewall SPX – pre-auth RCE przez zapis dowolnych plików

CVE-2025-7624CRITICAL9.8PL ✓same product

SQL Injection w Sophos Firewall SMTP Proxy prowadzące do RCE

CVE-2024-12727CRITICAL9.8PL ✓same product

Pre-auth SQL injection w Sophos Firewall umożliwiający RCE

CVE-2024-13974HIGH8.1same product

A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1...