7.2

CVE-2022-1807

Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sophos ≫ Firewall Version < 18.5
Sophos ≫ Firewall Version 18.5 Update -
Sophos ≫ Firewall Version 18.5 Update mr1
Sophos ≫ Firewall Version 18.5 Update mr1-1
Sophos ≫ Firewall Version 18.5 Update mr2
Sophos ≫ Firewall Version 18.5 Update mr3
Sophos ≫ Firewall Version 19.0 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.02% 0.604
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
security-alert@sophos.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-18-5-4
Vendor Advisory
https://www.sophos.com/en-us/security-advisories/sophos-sa-20220907-sfos-19-0-1
Vendor Advisory