CRITICAL

CVE-2020-29574

Sophos Cyberoamos 2020-12-11 CVSS v3.1
CVSS
9.8
KEV

Description

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely.

Summary dbcve.org

An unauthenticated SQL injection vulnerability exists in the WebAdmin interface of Cyberoam OS. Remote attackers can exploit this to execute arbitrary SQL statements, potentially allowing database compromise, credential theft, or full system takeover.

Mitigation

Immediately restrict network access to the WebAdmin interface (it should never be internet-facing) and apply any available vendor patches for Cyberoam OS. If no patch exists, consider compensating controls such as VPN access or moving to a supported platform.

Weakness (CWE)

CWE-89 SQL Injection

EPSS Score

4.66%
Probability of exploitation in next 30 days
91.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE