CVE-2024-12727

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Dec 19, 2024
CWE ID 89

Summary

CVE-2024-12727 is a pre-authentication SQL injection vulnerability affecting the email protection feature in Sophos Firewall versions prior to 21.0 MR1 (21.0.1). It grants unauthorized access to the reporting database. In certain configurations involving Secure PDF eXchange (SPX) and High Availability (HA) mode, this vulnerability could potentially enable remote code execution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share