VYPR

XG Firewall

by Sophos

CVEs (23)

  • CVE-2022-1040CriKEVMar 25, 2022
    risk 0.87cvss 9.8epss 1.00

    An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

  • CVE-2022-3236CriKEVSep 23, 2022
    risk 0.84cvss 9.8epss 0.99

    A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

  • CVE-2020-15069CriKEVJun 29, 2020
    risk 0.77cvss 9.8epss 0.11

    Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x.

  • CVE-2024-12727CriDec 19, 2024
    risk 0.64cvss 9.8epss 0.01

    A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in…

  • CVE-2020-15504CriJul 10, 2020
    risk 0.64cvss 9.8epss 0.02

    A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13…

  • CVE-2020-11503CriJun 18, 2020
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely.

  • CVE-2018-16117HigJun 20, 2019
    risk 0.61cvss 8.8epss 0.44

    A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST parameter.

  • CVE-2020-17352HigAug 7, 2020
    risk 0.58cvss 8.8epss 0.04

    Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.

  • CVE-2024-12729HigDec 19, 2024
    risk 0.57cvss 8.8epss 0.01

    A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

  • CVE-2022-3713HigDec 1, 2022
    risk 0.57cvss 8.8epss 0.01

    A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2018-16116HigJun 20, 2019
    risk 0.57cvss 8.8epss 0.02

    SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parameter.

  • CVE-2021-25268HigMay 5, 2022
    risk 0.55cvss 8.4epss 0.01

    Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.

  • CVE-2024-13974HigJul 21, 2025
    risk 0.53cvss 8.1epss 0.07

    A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the firewall’s DNS environment to achieve remote code execution.

  • CVE-2018-16118HigJun 20, 2019
    risk 0.53cvss 8.1epss 0.04

    A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.

  • CVE-2022-3226HigDec 1, 2022
    risk 0.47cvss 7.2epss 0.02

    An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.

  • CVE-2022-1807HigSep 7, 2022
    risk 0.47cvss 7.2epss 0.01

    Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.

  • CVE-2024-13973MedJul 21, 2025
    risk 0.45cvss 6.8epss 0.08

    A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators achieving arbitrary code execution.

  • CVE-2022-3709MedDec 1, 2022
    risk 0.44cvss 6.8epss 0.01

    A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2021-25267MedMay 5, 2022
    risk 0.44cvss 6.8epss 0.01

    Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.

  • CVE-2017-18014MedJan 12, 2018
    risk 0.40cvss 6.1epss 0.02

    An NC-25986 issue was discovered in the Logging subsystem of Sophos XG Firewall with SFOS before 17.0.3 MR3. An unauthenticated user can trigger a persistent XSS vulnerability found in the WAF log page (Control Center -> Log Viewer -> in the filter option "Web Server…

Page 1 of 2