CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.
Other sources
CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue utilization of CyberoamOS (CROS) because the WebAdmin SQL injection vulnerability (unauthenticated remote arbitrary SQL execution) affects the impacted product, which is end-of-life (EoL) and/or end-of-service (EoS).
Event History
Frequently Asked Questions
What is CVE-2020-29574?
CVE-2020-29574 is an SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 that allows unauthenticated attackers to execute arbitrary SQL statements remotely.
How severe is CVE-2020-29574?
CVE-2020-29574 has a severity rating of 9.8 (critical).
How does CVE-2020-29574 impact Sophos Cyberoam OS?
CVE-2020-29574 allows unauthenticated attackers to remotely execute arbitrary SQL statements in Sophos Cyberoam OS through 2020-12-04.
What is the Common Weakness Enumeration (CWE) for CVE-2020-29574?
The CWE for CVE-2020-29574 is CWE-89 (SQL Injection).
Are there any references for CVE-2020-29574?
Yes, you can find more information about CVE-2020-29574 at the following references: [link1](https://www.bleepingcomputer.com/news/security/sophos-fixes-sql-injection-vulnerability-in-their-cyberoam-os/) [link2](https://www.cyberoam.com/ngfw.html)