CVE-2024-12727
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Dec 19, 2024
CWE ID 89
Summary
CVE-2024-12727 is a pre-authentication SQL injection vulnerability affecting the email protection feature in Sophos Firewall versions prior to 21.0 MR1 (21.0.1). It grants unauthorized access to the reporting database. In certain configurations involving Secure PDF eXchange (SPX) and High Availability (HA) mode, this vulnerability could potentially enable remote code execution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sophos Firewall
Affected Vendors
- Sophos