CVE-2020-29574

CRITICAL KEV

Cyberoam OS - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-29574 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added February 6, 2025.

Description

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

Scores

CVSS v3 9.8
EPSS 0.1007
EPSS Percentile 93.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2025-02-06
VulnCheck KEV 2024-10-31
ENISA EUVD EUVD-2020-21936
CWE
CWE-89
Status published
Products (1)
sophos/cyberoamos < 2020-12-04
Published Dec 11, 2020
KEV Added Feb 06, 2025
Tracked Since Feb 18, 2026