A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Nov 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sophos
Sophos firewall Sophos firewall Firmware |
|
| CPEs | cpe:2.3:h:sophos:firewall:-:*:*:*:*:*:*:* cpe:2.3:o:sophos:firewall_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sophos
Sophos firewall Sophos firewall Firmware |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 19 Dec 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Sophos
Published: 2024-12-19T20:26:59.325Z
Updated: 2024-12-21T04:55:59.875Z
Reserved: 2024-12-17T18:21:52.796Z
Link: CVE-2024-12727
Updated: 2024-12-20T17:02:58.053Z
Status : Analyzed
Published: 2024-12-19T21:15:07.740
Modified: 2025-11-12T19:27:32.093
Link: CVE-2024-12727
No data.