First published: Thu May 05 2022(Updated: )
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Firewall Firmware | <19.0 | |
Sophos Firewall |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-25267 is high with a CVSS score of 8.4.
CVE-2021-25267 allows for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.
Upgrade to Sophos Firewall version 19.0 or later to fix CVE-2021-25267.
Yes, Sophos Firewall older than version 19.0 GA is affected by CVE-2021-25267.
The Common Weakness Enumeration (CWE) ID for CVE-2021-25267 is 79.