PT-2025-30273 · Sophos · Sophos Firewall

CVE-2025-7624

·

Publicado

2025-07-21

·

Atualizado

2025-11-17

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sophos Firewall versions prior to 21.0 MR2 (21.0.2)
Description An SQL injection vulnerability exists in the legacy (transparent) SMTP proxy. Successful exploitation can lead to remote code execution if a quarantining policy is active for Email and the Sophos Firewall Operating System (SFOS) was upgraded from a version older than 21.0 GA.
Recommendations Update Sophos Firewall to version 21.0 MR2 (21.0.2) or later.

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-14339
CVE-2025-7624

Produtos afetados

Sophos Firewall