Sophos Security Update – 22 December 2024

Sophos has released security updates to fix multiple vulnerabilities in Sophos firewall versions 21.0 GA (21.0.0) and older.

The severity of the addressed vulnerability could allow the remote attacker to execute remote code and gain access to the affected versions.

1. Sophos firewall pre-auth SQL injection vulnerability (CVE-2024-12727):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

2. Sophos firewall post-auth code injection Vulnerability (CVE-2024-12729):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Access
Vulnerabilities
  • CVE-2024-12727
  • CVE-2024-12728
  • CVE-2024-12729
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Sophos Security Advisory

References