VendorsSophosunified_threat_managementall versions
Vulnerabilities

Sophos Unified Threat Management (UTM)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
Published 2020-09-25 · Analyzed
10.0KEVEPSS 0.968
CVE-2022-0386
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
Published 2022-03-21 · Modified
8.8EPSS 0.012
CVE-2014-2537
Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Published 2014-03-18 · Modified
7.8EPSS 0.031
CVE-2022-0652
Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to attempt off-line brute-force attacks against these password hashes in Sophos UTM before version 9.710.
Published 2022-03-21 · Modified
7.8EPSS 0.002
CVE-2016-0777
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.
Published 2016-01-14 · Modified
6.5EPSS 0.635
CVE-2021-25273
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
Published 2021-07-29 · Modified
4.8EPSS 0.008
CVE-2012-3238
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
Published 2012-07-09 · Modified
4.3EPSS 0.035