CVE-2021-25268

HIGH

Sophos Firewall <19.0 GA - Privilege Escalation

Title source: llm
STIX 2.1

Description

Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.

References (1)

Core 1
Core References

Scores

CVSS v3 8.4
EPSS 0.0018
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
sophos/firewall_firmware < 19.0
Published May 05, 2022
Tracked Since Feb 18, 2026