Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51075 | A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sophos
Sophos firewall Sophos firewall Firmware |
|
| CPEs | cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:* cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sophos
Sophos firewall Sophos firewall Firmware |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Dec 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Sophos
Published:
Updated: 2024-12-21T04:55:59.875Z
Reserved: 2024-12-17T18:21:52.796Z
Link: CVE-2024-12727
Updated: 2024-12-20T17:02:58.053Z
Status : Analyzed
Published: 2024-12-19T21:15:07.740
Modified: 2025-11-12T19:27:32.093
Link: CVE-2024-12727
No data.
OpenCVE Enrichment
No data.
EUVD