CVE-2021-25268: XSS
Published May 5, 2022
·Updated
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
Affected Software
2 affected components
Sophos Firewall Firmware<19.0
Sophos Firewall
Event History
May 5, 2022
CVE Published
via MITRE·06:05 PM
Data Sourced
via MITRE·06:05 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-25268.
2
What is the severity rating of CVE-2021-25268?
CVE-2021-25268 has a severity rating of 8.4 (high).
3
How can this vulnerability be exploited?
This vulnerability can be exploited through multiple XSS vulnerabilities in Webadmin, allowing for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.
4
Which version of Sophos Firewall is affected by this vulnerability?
Sophos Firewall older than version 19.0 GA is affected by this vulnerability.
5
Is there a fix available for CVE-2021-25268?
Yes, it is recommended to upgrade to Sophos Firewall version 19.0 GA or later to address this vulnerability.