Description
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-43067 | A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA. |
References
History
Wed, 23 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Sophos
Published:
Updated: 2025-04-23T20:23:36.334Z
Reserved: 2022-10-27T00:00:00.000Z
Link: CVE-2022-3710
Updated: 2024-08-03T01:20:57.030Z
Status : Modified
Published: 2022-12-01T18:15:10.453
Modified: 2025-04-23T21:15:16.453
Link: CVE-2022-3710
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD