logo

Multiple Vulnerabilities in Sophos Firewall Could Allow for Remote Code Execution

ID: bf1321e9-c8c6-53d1-8f62-e57d2f3d0247

STIX ID: report--bf1321e9-c8c6-53d1-8f62-e57d2f3d0247

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2024-12-20

Date Updated: 2026-04-27

...
...

Multiple critical vulnerabilities were disclosed in Sophos Firewall: a pre-auth SQL injection in the email protection feature enabling remote code execution (CVE-2024-12727), a post-auth code injection in the User Portal enabling RCE (CVE-2024-12729), and an HA SSH passphrase exposure that could reveal a privileged account (CVE-2024-12728). Successful exploitation could provide unauthorized system access and allow attackers to view, modify, or delete data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.