CVE-2024-12728: Critical severity sophos firewall firmware vulnerability
Published Dec 19, 2024
·Updated
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).
Affected Software
3 affected components
Sophos Firewall<20.0.3
All of the following
Sophos Firewall Firmware<20.0.3
Sophos Firewall
Remediation
Event History
Dec 19, 2024
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Dec 20, 2024
News Published
via BleepingComputer·03:31 PM
News Published
via BleepingComputer·03:32 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-12728?
CVE-2024-12728 is considered a critical vulnerability due to the potential for privileged system access via SSH.
2
How do I fix CVE-2024-12728?
To address CVE-2024-12728, upgrade your Sophos Firewall to version 20.0 MR3 (20.0.3) or a later version.
3
What systems are affected by CVE-2024-12728?
CVE-2024-12728 affects Sophos Firewall versions older than 20.0 MR3 (20.0.3).
4
What type of vulnerability is CVE-2024-12728?
CVE-2024-12728 is categorized as a weak credentials vulnerability.
5
Can exploiting CVE-2024-12728 allow unauthorized access?
Yes, exploiting CVE-2024-12728 can potentially allow unauthorized privileged system access.