CVE-2024-12727: SQL Injection
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12727?
CVE-2024-12727 is considered critical due to the potential for remote code execution.
How do I fix CVE-2024-12727?
To fix CVE-2024-12727, upgrade Sophos Firewall to version 21.0.1 or later.
What feature is affected by CVE-2024-12727?
CVE-2024-12727 affects the email protection feature of Sophos Firewall.
What can exploit CVE-2024-12727?
Exploitation of CVE-2024-12727 can lead to unauthorized access to the reporting database.
Which versions of Sophos Firewall are vulnerable to CVE-2024-12727?
Sophos Firewall versions prior to 21.0 MR1 (21.0.1) are vulnerable to CVE-2024-12727.