Sophos discloses critical Firewall remote code execution flaw
ID: 436b6d99-e43e-5286-99f0-7d7b80499269
STIX ID: report--436b6d99-e43e-5286-99f0-7d7b80499269
Feed Name: Bleeping Computer
Sophos disclosed three vulnerabilities in Sophos Firewall (CVE-2024-12727, CVE-2024-12728, CVE-2024-12729) that can allow pre-auth SQL injection with potential remote code execution in a specific SPX+HA configuration, predictable SSH passphrases enabling unauthorized privileged access during HA initialization, and an authenticated code injection in the User Portal. The vendor published hotfixes (installed by default) and permanent fixes in newer firmware, provided mitigation guidance (restrict SSH, avoid exposing management interfaces), and estimated that the issues affect a small percentage of deployed devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
