A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
History

Fri, 20 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Dec 2024 20:45:00 +0000

Type Values Removed Values Added
Description A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Sophos

Published: 2024-12-19T20:26:59.325Z

Updated: 2024-12-21T04:55:59.875Z

Reserved: 2024-12-17T18:21:52.796Z

Link: CVE-2024-12727

cve-icon Vulnrichment

Updated: 2024-12-20T17:02:58.053Z

cve-icon NVD

Status : Received

Published: 2024-12-19T21:15:07.740

Modified: 2024-12-19T21:15:07.740

Link: CVE-2024-12727

cve-icon Redhat

No data.