A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
2022-12-01T18:15:10.453
2025-04-23T21:15:16.453
Modified
CVSSv3.1: 2.7 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | sophos | xg_firewall_firmware | < 19.5 | Yes |
Hardware | sophos | xg_firewall | - | No |