Critical severity9.8NVD Advisory· Published Nov 16, 2022· Updated Jun 17, 2026
CVE-2022-3980
CVE-2022-3980
Description
An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Sophos/Sophos Mobile managed on-premisesv5Range: 5.0.0
Patches
Vulnerability mechanics
References
1- www.sophos.com/en-us/security-advisories/sophos-sa-20221116-smc-xeenvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.