CVE-2024-12729
HIGHSophos Firewall Firmware < 21.0.1 - Code Injection
Title source: ruleDescription
A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).
Scores
CVSS v3
8.8
EPSS
0.0032
EPSS Percentile
55.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-94
Status
published
Affected Products (1)
sophos/firewall_firmware
< 21.0.1
Timeline
Published
Dec 19, 2024
Tracked Since
Feb 18, 2026